Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily.
Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can blend in with legitimate site functionality, making detection significantly harder.
Once embedded into a compromised site, these containers allow hackers to inject custom JavaScript and HTML, enabling them to harvest sensitive payment data during checkout.
Recent investigations uncovered a spike in malicious Google Tag Manager containers actively used in web skimming campaigns.
One widely detected container, GTM-WJ6S9J6, appeared on at least 178 infected sites in 2023 and was ultimately removed by Google following abuse reports. However, before its takedown, it injected skimmer payloads from domains like gtm-statistic [.]com.
Security researchers in Sucuri warn that attackers only need a basic Google account to create a GTM container and begin distributing malicious code.
Attackers also registered lookalike domains such as gooqle-analytics[.]com and webstatlstics[.]com to impersonate legitimate analytics services and evade suspicion.

In some cases, multiple GTM scripts were chained together to deploy skimmers, complicating detection and analysis.
Magecart Hackers Exploit Google Tag Manager
A newer campaign involving container GTM-TVKQ79ZS revealed an updated version of the long-running ATMZOW skimmer.

This malware family has been active since at least 2015 and was previously linked to large-scale Magento compromises during the early Magecart era.
Despite years of exposure, the group behind ATMZOW continues to refine its techniques. The latest variant uses heavily obfuscated JavaScript that depends on the exact script length, making it fragile to analyze but highly resistant to traditional decoding methods.
For example, earlier variants used simple Base64 encoding to hide trigger conditions like targeting checkout pages.
In contrast, the newer code layers multiple decoding routines, requiring precise reconstruction before analysts can extract meaningful indicators.
One of the most notable changes is the use of 40 newly registered domains designed to appear benign. These domains follow a pattern combining art-related terms with analytics-style keywords, such as cdn.sketchanalyticsvault[.]com and cdn.visualartinsights[.]com.

Instead of loading all domains at once, the malware randomly selects two domains per infected browser session and stores them locally. This tactic limits visibility during traffic analysis, slowing down efforts to identify and block the full infrastructure.
Additionally, the domains were initially hidden behind Cloudflare protection to mask their origin.
Once uncovered, researchers traced them to Hostinger infrastructure, with IPs including 31.220.21[.]211 and 62.72.7[.]89. These same IPs were linked to earlier skimming campaigns, indicating infrastructure reuse.
Even after Google removed malicious containers like GTM-TVKQ79ZS, attackers quickly adapted by deploying new containers such as GTM-NTV2JTB4 and GTM-MX7L8F2M.
This rapid recycling highlights the persistence of Magecart groups and their ability to reinfect vulnerable sites.
In some cases, GTM-based skimmers were found alongside other threats, including WebSocket-based skimmers, suggesting attackers are layering multiple techniques to maximize data theft.
While many modern skimming campaigns have shifted toward WooCommerce platforms, ATMZOW continues to heavily target Magento-based ecommerce environments. This indicates that older, often unpatched Magento installations remain a lucrative target.
Security experts emphasize that GTM scripts should not be blindly trusted, even though they originate from a reputable domain. Any unauthorized or unfamiliar GTM container embedded in a website may indicate a compromise.
A practical example: if a checkout page suddenly loads additional scripts from unknown domains or triggers unexpected network requests, it could signal an active skimmer. Regular audits of GTM configurations and strict access controls are critical to preventing such attacks.
As Magecart groups continue to evolve, the abuse of trusted services like Google Tag Manager underscores a broader trend attackers are increasingly hiding in plain sight, leveraging legitimate tools to carry out large-scale payment data theft.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





