SOURCE DEFENSE RESEARCH INTELLIGENCE NEWSJune 3, 2025 |
![]() |
MAGECART RETURNS: THREAT ACTORS REBRAND GTM-HIDING ATTACKS
The Source Defense Research Team has observed an infrastructure shift in a persistent Magecart campaign. The attackers have reactivated a previously dormant domain—jqueri[.]at—continuing their established strategy of hiding malicious scripts behind Google Tag Manager (GTM) containers. This move is part of an ongoing effort to stay ahead of domain blacklists and maintain a foothold across targeted websites. |
|
Attack summary
Over the past year, our team has tracked the use of GTM containers to inject innocent-looking scripts tied to the following domains served from the same IP address:
Although jqueri[.]at had remained inactive during that time, in May 2025 we detected a shift:
This evidence points to an intentional rebranding by the attackers—designed to circumvent static domain blocks while continuing to operate via GTM infrastructure. |
|
Key Takeaways
|
|
How does Source Defense protect you
Intelligence-driven threat detection: Continuous monitoring of GTM behavior and domain reassignments allows us to quickly identify and block threats. Real-time protection with Protect: Customers using this product receive automated blocking for scripts tied to known malicious GTMs or domains. Proactive alerts with Detect: Customers are notified when:
|
|
As attackers adapt their tactics, staying ahead requires real-time visibility, rapid response, and deep understanding of client-side threats—exactly what Source Defense delivers. |
|
Any questions? Contact us at: support@sourcedefense.com For the latest cyber research news, follow us at https://x.com/sdcyberresearch |
|
|