s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811958 high

📛 Threat Title

magecart: Domain used for credit card skimming (usually related to Magecart attacks) hidoslsk.shop

Category: magecart Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain hidoslsk.shop UrlVoid 4 / 35

IOC database

Type
domain
Value
hidoslsk.shop
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain used for credit card skimming (usually related to Magecart attacks) attributed to magecart

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.

Remediations (10)

  • web:any.run

    Active Magecart Campaign Targets Spain, Steals Card Data via Hijacked eStores for Bank Fraud A large-scale magecart operation remained active for over 24 months, leveraging an infrastructure of 100+ domains . While the targeted victims are e-commerce websites, the actual pressure falls on banks and payment systems.

  • web:cside.com

    What is Magecart : Complete Guide and Prevention Strategy Magecart attacks steal card data in the browser before traditional tools detect them. Learn how Magecart attacks work and entry points used by attackers.

  • web:cyberpress.org

    By exploiting this platform, a notorious Magecart group is silently injecting custom scripts into e-commerce sites to siphon customer credit card details. This tactic turns a legitimate, highly trusted domain into a devastating weapon for digital skimming . Magecart Abuses Tag Manager

  • web:cybersecuritynews.com

    Magecart hackers used more than 100 domains to hijack eStore checkouts and steal card data, exposing a long-running global payment skimming campaign.

  • web:visualping.io

    Learn what Magecart is, how web skimming attacks steal payment data from e-commerce sites, and discover proven strategies to protect your online store in 2025.

  • web:www.csoonline.com

    Hacking groups that make up Magecart are effective and persistent at stealing customer and payment card data through skimmers. Here's how they work and what you can do to mitigate the risk.

  • web:www.feroot.com

    Learn how to detect and prevent Magecart attacks that bypass WAFs and steal credit card data. Complete CISO guide with PCI compliance requirements.

  • web:www.humansecurity.com

    A Magecart attack is one in which cybercriminals skim shoppers' credit card data and other personally identifiable information (PII) from your online payment forms when they complete a transaction. The name " Magecart " refers to several hacker groups that use online skimming techniques to steal payment data from e-commerce sites on the Magento platform. However, Magecart attacks have ...

  • web:www.imperva.com

    What Is Magecart ? The name " Magecart " refers to several hacker groups that employ online skimming techniques for the purpose of stealing personal data from websites—most commonly, customer details and credit card information on websites that accept online payments. Magecart groups have successfully breached well-known brands.

  • web:www.malwarebytes.com

    A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.