Follow our news and updates
Get marketing tips, how-to's, and more!
Follow our news and updates
Get marketing tips, how-to's, and more!
Follow our news and updates
Get marketing tips, how-to's, and more!
Follow our news and updates
Get marketing tips, how-to's, and more!
In a concerning development, cybercriminals are leveraging Google Tag Manager (GTM) to inject malicious scripts into Magento-based eCommerce websites. This sophisticated attack enables the theft of customers' credit card details during the checkout process, posing significant risks to both businesses and consumers.
Google Tag Manager is a widely used tool that allows website administrators to manage and deploy marketing tags without modifying the code directly. Unfortunately, hackers have identified a method to exploit GTM by injecting obfuscated scripts that remain undetected. Once embedded, these scripts capture sensitive payment information entered by customers.
The primary victims of this attack are websites operating on the Magento platform. Researchers from Sucuri have discovered that the malicious code is often loaded from the cms_block.content database table. Additionally, attackers employ a hidden PHP backdoor located at ./media/index.php to maintain persistent access and continuously siphon user data.
Sucuri's investigation revealed that at least six websites were compromised using a specific GTM ID associated with the domain eurowebmonitortool[.]com, which has been blacklisted by multiple security vendors. This indicates an active and widespread campaign targeting vulnerable eCommerce sites.
To protect your website and customers from such intrusions, consider implementing the following steps:
The exploitation of Google Tag Manager to deploy credit card skimmers underscores the evolving tactics of cybercriminals. By staying informed and proactively implementing robust security protocols, businesses can safeguard their digital assets and maintain customer trust.
These Stories on Web Development
Meet Us (By Appointment):
677 N Washington Blvd, Suite 45 Sarasota, FL 34236
Call: (941) 444-1945
Email: hello@theiamedia.agency