Search
Close this search box.

PSA: Malicious Scripts Posing as Google Tracking

The folks over at Sucuri have uncovered a new security threat involving malicious scripts posing as legitimate Google tracking calls in order to avoid casual detection. These scripts are designed to scrape sensitive data such as credit card information from compromised websites.

The malicious code attempts to mimic references to the standard Google Analytics and Google Tag Manager libraries using nearly identical URLs, in some cases registered using alternative TLDs.

In the below example, a malicious script uses a Cameroonian TLD to mimic a reference to the standard Google Analytics library.

Legitimate www.google-analytics.com/analytics.js‌

Malicious ‌www.google-analytics.cm/analytics.js

And below a malicious script is hosted on a domain registered under the standard ‘.com’ TLD but with a single letter change ‘q’ causing the malicious script to be loaded from a domain not owned by Google.

Legitimate www.googletagmanager.com/gtm.js‌

Malicious www.gooqletagmanager.com/gtm.js

According to Sucuri, inspections of the malicious code reveal its true intention is to harvest sensitive details from form fields including credit-card details entered during checkout.

Possibly more alarming, Sucuri also outlines an attack vector involving equally obfuscated malicious code mimicking standard Google tracking calls embedded directly within sensitive forms. Suggesting that these sites have at some point, been compromised through targeted hacking and that the administrators of these sites have been unable to differentiate these calls from legitimate tracking.

To be sure none of these techniques are new, however the obfuscation by mimicking legitimate Google tracking calls is somewhat alarming given the significant use of Google tracking scripts across the web.

Other than being aware that such threats exists, we recommend that site administrators scan their sites for references to all of the malicious domains and libraries outlined in the original post.

The content and advice contained in this post may be out of date. Last updated on April 9, 2019.

Contact us

to discuss a range of services and support to suit your business needs and goals.

* Required field

Latest Blog Posts

VWO Test

Chief Marking Officers are in a perpetual balancing act, demonstrating ROI from marketing activities under the scrutiny of the Chief Financial Officer.

Read More »

Need Some Help?

We can work onsite or remotely with you and your team to provide capacity uplift or ongoing support as you need.

Need additional MarTech resources to supplement your team for special projects or to provide given expertise?

Data quality and integrity is key to any data strategy. We undertake audits and health checks that can give you peace of mind.

If you know your data could be working harder, but you’re not sure where to start, we can help.

We can help you build dynamic dashboards based on important metrics to fully inform the business.

Is it a CDP or a DMP that is right for your organisation? Let us help you work through the pros and cons.

Let us show you how to bring your online and offline data together to create a best picture of your customers.

Free assessments

Martech Talks: The Four Stages Of Attribution Excellence

This webinar was recorded in April 2024.

Download the full 2024 Digital Experience Benchmarks report from Contentsquare.

Note that the information contained in this presentation should not be taken as legal advice. Digital Balance and its partners recommend that you undertake your own legal investigation.

Martech Talks: The Four Stages Of Attribution Excellence

This webinar was recorded in October 2023.

Note that the information contained in this presentation should not be taken as legal advice. Digital Balance and its partners recommend that you undertake your own legal investigation.

Martech Talks: Privacy and Data Governance

This webinar was recorded in August 2023.

Note that the information contained in this presentation should not be taken as legal advice. Digital Balance and its partners recommend that you undertake your own legal investigation.

Martech Talks: Privacy Changes and Data Security

This webinar was recorded in July 2023.

 

Note that the information contained in this presentation should not be taken as legal advice. Digital Balance and its partners recommend that you undertake your own legal investigation.