The discovery of a new skimmer variant – Grelos – reveals the difficulties associated with detecting various Magecart campaigns.
On Wednesday, RiskIQ researchers described how a new Grelos Skimmer showed “increased overlap” in Magecart’s infrastructure and teams, with this malware – along with other forms of skimmers – now hosted on domain infrastructures used by multiple teams or connected via WHOIS records, known phishing campaigns,and the deployment of other malware, creating “unions” that can be difficult to separate.

Magecart is a term used to describe phishing and threat campaigns by actors who specialize in stealing payment card data from e-commerce websites.
Several years ago, well-known brands like British Airways and Ticketmaster became the first major victims of this form of attack, and since then, countless websites have fallen victim to the same technique.
The new variant of the Grelos skimmer, malware that has been around since at least 2015 and is associated with the Magecart 1 and 2 groups, resembles a separate strain described by researcher @AffableKraut in July. This variant is a WebSocket-based skimmer that uses base64 to hide activities .
“We believe this skimmer is not directly related to Group 1-2 activity from 2015-16, but is instead a re-implementation of some of their code,” says RiskIQ. “This version of the skimmer features a ‘loader stage’ and a ‘skimmer stage’ – both of which are quintuple base64 encoded.”
Following a Magecart attack on Boom! Mobile, RiskIQ examined the attack, in which the Fullz House group uploaded malicious JavaScript to the mobile network provider to harvest customer data.
The domains used in this cyberattack led the group to a cookie and related skimmer websites, including facebookapimanager[.]com and googleapimanager[.]com.
However, instead of finding the Fullz House Skimmer, researchers discovered a new skimmer variant called Grelos. This strain has a similar base64-encoded “loader stage,” but only has one encoding layer, duplicate script tags, misspellings, and includes a dictionary called “translate” that contains phrases used by fake payment created by the malware. Web sockets are still used for data exfiltration.
RiskIQ has observed several new skimmer variants related to Magecart in recent years. The company says the Fullz House skimmer has been picked up by other hacking groups, even leveraging some of the same infrastructure – such as hosting providers – to host other skimmers, including Grelos, which also shares IPs with the Inter skimmer.
This, in turn, creates a “murkiness” in terms of monitoring the activities of separate Magecart groups, many of which actively launch new attacks against e-commerce on a daily basis.
