Magecart are cyberattacksin which hackers insert malicious code into websites with the aim of stealing credit card information during user checkout.
Such groups are therefore changing course. The new tactic, which they have called “spray-and-pray,” attacks sites entirely, in the hope of being able to insert the code into the online store. The “hack all” strategy, although it does not seem particularly professional, is already paying off.

In fact, more than 17,000 domains have been infected by Magecart groups since April.
According to RiskIQ, the hackers were looking for misconfigured AWS S3 storage servers. They then injected their code into JavaScript on live sites. This code, like any other Magecart code, was designed to capture card details entered into payment forms and send the data to the appropriate servers.
RiskIQ's head of threat research, Yonathan Klijnsma, said that the group behind these attacks is new and relies primarily on the Inter Skimmer Kit.

Essentially, what the Magecart hackers are doing here is no different than what most security on a daily basis for their jobs: they use automated AWS S3 scanners to look for S3 buckets that have been neglected by their owners.
Klijnsma emphasized that while one would expect that as hacking trends change, such attacks would stop, on the contrary, web skimming seems to be growing and evolving.
According to Klijnsma, Magecart web skimming is divided into four categories.
- High-level groups that use web skimming as a tool, but not as the main attack.
- Groups that place particular emphasis on developing their skimming skills.
- Homemade skimmers that have reduced performance and are rarely seen.
- Junior teams using the Inter Skimmer Kit.
