CosmicSting campaign sttack details
The broader CosmicSting campaign remains ongoing, despite earlier disclosures. Our research confirms infections on hundreds of websites globally, with attackers using fresh domains — all previously unlisted on major blacklists - to slip past conventional defenses unnoticed.
The communication method continues to leverage WebSocket connections, with the Magecart payload embedded in the very first WebSocket message, further complicating detection.
This technique is especially effective on sites that believe they’re secure because they don’t process payment data directly. But the attack hits just before the protection kicks in — exposing the gap in coverage.
CosmicSting exploits a critical vulnerability — CVE-2024-34102 — which grants unauthorized access to private server files. When paired with the recently exposed Linux iconv bug, this vulnerability may even open the door to remote code execution — a rare and dangerous combination.
Dive deeper into the vulnerability details via our blog:
🔗 Critical Security Update for Adobe Commerce / Magento Users