MageCart__2020__Magecart_Skimming_Attack_Targets_Mobile_Users_of_Hotel_Chain_Booking_Websites.pdf
ID: ce312393-121c-47ef-b37f-2323a03c5402
STIX ID: report--ce312393-121c-47ef-b37f-2323a03c5402
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2020-02-11
Last Modified Date: 2020-02-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro discovered a Magecart skimming campaign that compromised the Roomleader "viewedHotels" JavaScript module used by hotel booking sites, injecting mobile-targeted skimmer code that replaces or alters payment forms to harvest cardholder data (including CVC) and exfiltrate it to googletrackmanager.com; the report includes analysis of the skimmer behavior, deployment tactics (mobile user-agent checks, debugger checks, RC4+XOR encoding), multilingual injected forms, and IoCs (domain and SHA-256 hash).
