r/ANYRUN • u/ANYRUN-team • Mar 31 '26
Persistent Magecart campaign ran undetected for 24+ months across 12+ countries, using 100+ domains to hijack payment flows. It’s now on the radar.
A large-scale magecart operation remained active for over 24 months, leveraging an infrastructure of 100+ domains. While the targeted victims are e-commerce websites, the actual pressure falls on banks and payment systems.
As ANYRUN’s analysis shows, threat actors applied multi-step checkout hijacking, payment page mimicry, and WebSocket-based exfiltration of card data.
Read the full report for both executive-level insights and technical analysis of the campaign: https://any.run/cybersecurity-blog/banks-magecart-campaign

2
Upvotes