Skip to main content

GrelosGTM group abuses Google Tag Manager to attack e-commerce websites

0
Medium
Published: 09/15/2026 (09/15/2026, 08:15:42 UTC)
Source: AlienVault OTX General

Description

A cybercriminal group dubbed GrelosGTM has been exploiting Google Tag Manager's legitimate functionality to compromise e-commerce websites. First detected in early April 2020, the group evolved their tactics by February 2021 to inject malicious Google Tag Manager scripts into targeted sites. The campaign affected at least seven websites running Magento CMS across Belgium, Italy, the United Kingdom, and the United States. Attackers inject custom Google Tag Manager scripts that load multi-stage JavaScript payloads through WebSocket connections. The final payload deploys a heavily obfuscated JavaScript sniffer designed to steal customers' payment card information during checkout using fake payment forms, with stolen data exfiltrated to attacker-controlled servers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 12:03:45 UTC

Technical Analysis

GrelosGTM is a threat actor group that exploits Google Tag Manager's legitimate script injection capabilities to compromise e-commerce sites, particularly those using Magento CMS. The attack involves injecting custom Google Tag Manager scripts that establish WebSocket connections to load multi-stage JavaScript payloads. The ultimate payload is a sophisticated, obfuscated JavaScript sniffer designed to capture payment card data during the checkout process via fake payment forms. This stolen data is then sent to attacker-controlled infrastructure. The campaign has been active since early 2020 and has targeted at least seven e-commerce websites in multiple countries.

Potential Impact

The attack results in the theft of customers' payment card information during the checkout process on compromised e-commerce websites. This can lead to financial fraud, loss of customer trust, and reputational damage for affected businesses. The use of legitimate Google Tag Manager functionality makes detection and prevention more challenging.

Defensive Guidance

No official patches or fixes are indicated for this threat as it exploits legitimate Google Tag Manager functionality rather than a software vulnerability. Mitigation should focus on securing Google Tag Manager accounts and configurations, including strict access controls, monitoring for unauthorized script changes, and validating all injected scripts. E-commerce site operators should review and restrict Google Tag Manager permissions and audit tags regularly. Since this is an abuse of legitimate features, vendor-managed fixes are not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/grelosgtm/"]
Adversary
GrelosGTM
Pulse Id
6aa8feaea12952dc69b265df

Indicators of Compromise

Domain

ValueDescriptionCopy
domainjqwereid.online
domainfountm.online
domaingstatcs.com
domainwebfaset.com
domainbulder.online

Threat ID: 6aa9303355bf5e2cf5c3fc12

Added to database: 09/15/2026, 11:46:59 UTC

Last enriched: 09/15/2026, 12:03:45 UTC

Last updated: 09/16/2026, 02:35:06 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses