TF-1811957
high
📛 Threat Title
magecart: Domain used for credit card skimming (usually related to Magecart attacks) dysimasyd.shop
Description
Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
dysimasyd.shop
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
dysimasyd.shop- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain used for credit card skimming (usually related to Magecart attacks) attributed to magecart
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.
Remediations (10)
-
web:aviatrix.ai
A massive 2026 Magecart web skimming campaign exploited checkout pages to steal credit card data from major payment providers. Learn risks, tactics, and compliance impact.
-
web:cside.com
What is Magecart : Complete Guide and Prevention Strategy Magecart attacks steal card data in the browser before traditional tools detect them. Learn how Magecart attacks work and entry points used by attackers.
-
web:cybersecuritynews.com
Magecart hackers used more than 100 domains to hijack eStore checkouts and steal card data, exposing a long-running global payment skimming campaign.
-
web:labs.pcioasis.com
A comprehensive deep-dive into Lab 1, exploring how basic Magecart attacks compromise e-commerce sites to steal credit card information.
-
web:sansec.io
Magecart definition Magecart is a type of cybercrime where transaction data is intercepted during the checkout of an online store. Magecart attacks are also known as web skimming , digital skimming or formjacking. In this article, you will read about the origin of Magecart , a list of famous attacks , a taxonomy of Magecart attack methods, and what you can do to prevent these attacks .
-
web:visualping.io
Learn what Magecart is, how web skimming attacks steal payment data from e-commerce sites, and discover proven strategies to protect your online store in 2025.
-
web:www.csoonline.com
Hacking groups that make up Magecart are effective and persistent at stealing customer and payment card data through skimmers. Here's how they work and what you can do to mitigate the risk.
-
web:www.humansecurity.com
A Magecart attack is one in which cybercriminals skim shoppers' credit card data and other personally identifiable information (PII) from your online payment forms when they complete a transaction. The name " Magecart " refers to several hacker groups that use online skimming techniques to steal payment data from e-commerce sites on the Magento platform. However, Magecart attacks have ...
-
web:www.imperva.com
What Is Magecart ? The name " Magecart " refers to several hacker groups that employ online skimming techniques for the purpose of stealing personal data from websites—most commonly, customer details and credit card information on websites that accept online payments. Magecart groups have successfully breached well-known brands.
-
web:www.malwarebytes.com
A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.