GrelosGTM group abuses Google Tag Manager to attack e-commerce websites
A cybercriminal group dubbed GrelosGTM has been exploiting Google Tag Manager's legitimate functionality to compromise e-commerce websites. First detected in early April 2020, the group evolved their tactics by February 2021 to inject malicious Google Tag Manager scripts into targeted sites. The campaign affected at least seven websites running Magento CMS across Belgium, Italy, the United Kingdom, and the United States. Attackers inject custom Google Tag Manager scripts that load multi-stage JavaScript payloads through WebSocket connections. The final payload deploys a heavily obfuscated JavaScript sniffer designed to steal customers' payment card information during checkout using fake payment forms, with stolen data exfiltrated to attacker-controlled servers.
AI Analysis
Technical Summary
GrelosGTM is a threat actor group that exploits Google Tag Manager's legitimate script injection capabilities to compromise e-commerce sites, particularly those using Magento CMS. The attack involves injecting custom Google Tag Manager scripts that establish WebSocket connections to load multi-stage JavaScript payloads. The ultimate payload is a sophisticated, obfuscated JavaScript sniffer designed to capture payment card data during the checkout process via fake payment forms. This stolen data is then sent to attacker-controlled infrastructure. The campaign has been active since early 2020 and has targeted at least seven e-commerce websites in multiple countries.
Potential Impact
The attack results in the theft of customers' payment card information during the checkout process on compromised e-commerce websites. This can lead to financial fraud, loss of customer trust, and reputational damage for affected businesses. The use of legitimate Google Tag Manager functionality makes detection and prevention more challenging.
Mitigation Recommendations
No official patches or fixes are indicated for this threat as it exploits legitimate Google Tag Manager functionality rather than a software vulnerability. Mitigation should focus on securing Google Tag Manager accounts and configurations, including strict access controls, monitoring for unauthorized script changes, and validating all injected scripts. E-commerce site operators should review and restrict Google Tag Manager permissions and audit tags regularly. Since this is an abuse of legitimate features, vendor-managed fixes are not applicable.
Affected Countries
United States, Belgium, Italy, United Kingdom
Indicators of Compromise
- domain: jqwereid.online
- domain: fountm.online
- domain: gstatcs.com
- domain: webfaset.com
- domain: bulder.online
GrelosGTM group abuses Google Tag Manager to attack e-commerce websites
Description
A cybercriminal group dubbed GrelosGTM has been exploiting Google Tag Manager's legitimate functionality to compromise e-commerce websites. First detected in early April 2020, the group evolved their tactics by February 2021 to inject malicious Google Tag Manager scripts into targeted sites. The campaign affected at least seven websites running Magento CMS across Belgium, Italy, the United Kingdom, and the United States. Attackers inject custom Google Tag Manager scripts that load multi-stage JavaScript payloads through WebSocket connections. The final payload deploys a heavily obfuscated JavaScript sniffer designed to steal customers' payment card information during checkout using fake payment forms, with stolen data exfiltrated to attacker-controlled servers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GrelosGTM is a threat actor group that exploits Google Tag Manager's legitimate script injection capabilities to compromise e-commerce sites, particularly those using Magento CMS. The attack involves injecting custom Google Tag Manager scripts that establish WebSocket connections to load multi-stage JavaScript payloads. The ultimate payload is a sophisticated, obfuscated JavaScript sniffer designed to capture payment card data during the checkout process via fake payment forms. This stolen data is then sent to attacker-controlled infrastructure. The campaign has been active since early 2020 and has targeted at least seven e-commerce websites in multiple countries.
Potential Impact
The attack results in the theft of customers' payment card information during the checkout process on compromised e-commerce websites. This can lead to financial fraud, loss of customer trust, and reputational damage for affected businesses. The use of legitimate Google Tag Manager functionality makes detection and prevention more challenging.
Defensive Guidance
No official patches or fixes are indicated for this threat as it exploits legitimate Google Tag Manager functionality rather than a software vulnerability. Mitigation should focus on securing Google Tag Manager accounts and configurations, including strict access controls, monitoring for unauthorized script changes, and validating all injected scripts. E-commerce site operators should review and restrict Google Tag Manager permissions and audit tags regularly. Since this is an abuse of legitimate features, vendor-managed fixes are not applicable.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/grelosgtm/"]
- Adversary
- GrelosGTM
- Pulse Id
- 6aa8feaea12952dc69b265df
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainjqwereid.online | — | |
domainfountm.online | — | |
domaingstatcs.com | — | |
domainwebfaset.com | — | |
domainbulder.online | — |
Threat ID: 6aa9303355bf5e2cf5c3fc12
Added to database: 09/15/2026, 11:46:59 UTC
Last enriched: 09/15/2026, 12:03:45 UTC
Last updated: 09/16/2026, 02:35:06 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.