Lockster hacker group breached over 3,800 stores through a critical Magento and Adobe Commerce vulnerability

28.09.2026 8 minutes Author: Newsman

An aggressive mass exploitation campaign over the past few weeks has compromised more than 3,800 online stores. The attacker exploited a critical vulnerability in Magento and Adobe Commerce to gain root access to servers, deploy payment card skimmers, and steal payment gateway keys and other data, putting store customers at risk.

From small local bookstores to major international brands, thousands of online stores have come under attack, potentially exposing their customers’ data to cybercriminals. The victims include a major French kitchenware retailer, a German wholesale supplier of screws and fasteners, a European computer hardware retailer, a Scandinavian seller of health, supplement, and wellness products, several automotive brand merchandise stores, and auto parts suppliers.

The malicious campaign was discovered on September 14, 2026. According to the available data, a single attacker began compromising online stores on a large scale around September 4. The threat actor calls itself Lockster, but left part of its own infrastructure unsecured and publicly accessible on the internet.

The exposed intermediate server contained data stolen from at least 3,834 identified websites, most of them online stores. It also hosted Lockster’s malicious code, tools, and other artifacts, along with portions of stolen data dumps, including private keys for the Braintree payment gateway. The exact number of compromised payment cards remains unknown because the malware sent most of the stolen records to other protected servers.

“Collectively, these websites processed at least 2 million orders in 2026,” said security researcher Aras Nazarovas.

Web directory of the exposed attacker.

Lockster is just one of several hacking groups exploiting a recently disclosed critical zero-day vulnerability in Magento and Adobe Commerce. The flaw was first identified by Sansec, which named it StyleSmuggler. The infrastructure and malicious tools uncovered in the campaign partially overlap with the indicators of compromise (IoCs) detailed in Sansec’s report on exploitation of the zero-day.

Adobe addressed StyleSmuggler with an emergency patch and urged administrators to update their systems immediately and rotate credentials.

The attacker tracked compromised stores, orders, and supported payment methods.

Hackers Collected Large Amounts of User Data

Lockster deployed payment card skimmers on compromised online stores. The malware intercepted credit and debit card details, along with other user information entered during checkout. The skimmer is polymorphic, meaning each compromised website receives a slightly modified version of the malicious code, making it harder for traditional antivirus tools to detect.

The malware targets the checkout form and collects the card number, CVV/CVC, expiration date, payment method, first and last name, address, phone number, and email address. It also records the store hostname, the browser’s User-Agent, and the transaction timestamp.

With root access, the attacker also decrypted and stole merchants’ private keys for payment gateways, including Braintree and Authorize.net, which stores use to process card payments. Valid merchant IDs combined with private keys could be abused for fraudulent charges and refunds, as well as to gain access to additional payment data.

“Ordinary visitors have no indication that the website may have been compromised,” Nazarovas warned.

The hacker also deployed a server-side sniffer to capture other sensitive data related to orders, keys, and store operations. For selected targets, the attacker carried out additional post-exploitation activity, including DNS poisoning, password hash cracking, CCTV camera probing, and password spraying.

“Some artifacts pointed to custom post-exploitation steps for specific targets. These include DNS poisoning, password hash cracking, CCTV camera probing, and password spraying,” Nazarovas said.

Stolen Braintree private keys.

Different types of stolen information were sent to several separate servers controlled by the attacker. The recovered data also indicates that Lockster attempted to extort money from its victims. Among the discovered artifacts was a ransom note sent to a casino, demanding $150,000.

A ransom note was found on the attacker’s server.

What Is Magento?

Adobe Commerce and Magento are based on the same e-commerce software. Adobe acquired Magento in 2018 for $1.68 billion and later rebranded the paid commercial versions of the platform as Adobe Commerce.

Magento is one of the major e-commerce platforms alongside Shopify and WooCommerce. It is used by large brands as well as thousands of smaller stores, with more than 150,000 active online stores currently running on Magento.

How Does Lockster Breach Servers?

The attacker used a precompiled list of stores known to be running Magento versions 2.4.2 through 2.4.9. No data was found on the server showing how the list had been assembled. The hacker may have used web infrastructure scanning services or custom crawlers.

To exploit an unauthenticated remote code execution (RCE) vulnerability and gain root access to a Magento server, the attacker sent a single HTTP POST request to the exposed /customer/address_file/upload endpoint. The attacker then uploaded a specially crafted polyglot GIF file that appeared to be a normal image but contained hidden executable PHP code.

The file was passed through the custom request field custom_attributes[country_id], while the system failed to properly validate the uploaded content. The POST request also used a special formatting trick to inject commands, causing web server system files to read and execute the hidden code.

The perpetrator calls himself “Lockster”.

Lockster also used several other known vulnerabilities for privilege escalation when needed.

“The source code and artifacts indicate that Lockster is running the primary campaign responsible for the initial exploitation of the zero-day vulnerability,” Nazarovas said.

The initial Sansec report details indicators of compromise associated with the zero-day exploitation campaign. The overlaps include domains used to exfiltrate payment card data, C2 infrastructure disguised as NTP traffic, and the kworker and fc-cache backdoors.

Polymorphic credit card skimmer – malware builder.

Based on timestamps found on the server, the attacker began carrying out certain post-exploitation activities on September 6, 2026. Although the recovered data contains no direct references to the use of artificial intelligence, the nature of the campaign suggests that agentic AI systems may have been used extensively for automation. Tasks were coordinated and tracked across numbered bots, while malicious scripts were repeatedly modified and refined to expand the campaign’s capabilities.

Three Backdoors and Protection From Rival Hackers

On compromised websites, Lockster established at least three different persistence mechanisms to maintain access. The first was a hidden system implant written in Rust. The background process was named kworker or fc-cache to blend in with legitimate system processes and maintained a covert, encrypted connection to a command-and-control (C2) server over NTP and WebSocket.

The second mechanism was backdoor access over SSH. The attacker created multiple system user accounts protected by secb_key cryptographic keys (Ed25519) and a shared password. The following usernames were used: cfgmgr, monclean, pkgsync, opsmaint, apppush, bakctl, pkgpulse, cachehook, dbaide, pkgprobe, jobaide, and tracguard.

The third mechanism involved additional Magento administrator accounts. The attacker stole existing administrator credentials and added its own accounts with administrative privileges to the platform.

In addition, Lockster appears to have been aware that other hackers were exploiting the same vulnerability, so it attempted to protect already compromised servers from rival attackers. It disabled six of the most commonly targeted administrator accounts and continuously tracked which compromised websites had already been patched. The attacker then took additional steps to preserve access or block competing hackers.

Software company Adobe. Photo by Samuel Boivin/NurPhoto via Getty Images.

The Server Still Needs to Be Checked After Patching

The exposed Lockster infrastructure once again highlights how important it is to update critically vulnerable systems as quickly as possible. However, simply installing Adobe’s emergency VULN-39341 (APSB26-146) patch is no longer enough. If a store was running a vulnerable version, it should be treated as potentially compromised.

Owners of Magento and Adobe Commerce stores are advised to inspect their servers for the indicators of compromise described in the Sansec report. Administrators should check for network connections to malicious domains, the presence of the kworker and fc-cache binaries, and the sk.js file used as a payment card skimmer. It may be located in /magento_root/pub/media/<...> or /magento_root/media/<...>.

Two Magento payment-related files should also be examined: PaymentInformationManagement.php and GuestPaymentInformationManagement.php. Administrators should look for the malicious strings fsnif2, fsnif1fsnif2c, and $fsn_a['x_host'].

“If any indicators of compromise are found, remove the backdoor binaries and the skimmer, reset all secret keys that may have been accessible from the compromised host, and audit both host administrator accounts and Magento administrator accounts to revoke the attacker’s access to the system,” Nazarovas said.

Information about the exposed attacker-controlled server was passed to the relevant authorities.

Indicators of Compromise

Domains:

js-static[.]io
checkout-cdn[.]com
ntpsync[.]io
ntp[.]reposync[.]to
ntp[.]synctime[.]to
ntp[.]syncstime[.]to

Vulnerabilities Used for Privilege Escalation:

  • CVE-2026-31431 «Copy Fail» (AF_ALG socket + splice + CMSG)

  • PwnKit, CVE-2021-4034

  • nf_tables LPE, CVE-2026-23111

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑