Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ScreamedJungle

Also known as: APT28, Pawn Storm, Fancy Bear, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, CosmicSting, Sednit, TG-0110, Newscaster, Hammertoss, Patchwork, CVE-2024-20720

Description

ScreamedJungle has emerged as a stealthy adversary that leverages known weaknesses in Magento e‑commerce platforms to gain unauthorised control of target websites. By executing drive‑by compromise via injected JavaScript hidden within HTML comment tags, the actor collects exhaustive browser fingerprint data from each site visitor and sends it to a secure Bablosoft server using cryptographically signed POST requests. The campaign relies on automated tools such as the Bablosoft BrowserAutomationStudio suite (Basic Automation Suite) and the FingerprintSwitcher module. PerfectCanvas technology is employed for pixel‑perfect replication of user fingerprints, ensuring high fidelity data for targeted exploitation. The actor’s modus operandi mirrors other large‑scale phishing and credential‑stuffing operations, hinting at a broader espionage agenda. ScreamedJungle has targeted over 115 Magento installations across multiple continents, harvesting hundreds of thousands of user fingerprints each month (e.g., an estimated 200,000 Italian fingerprints per month). The technique is notable for its low detectability: scripts are served from controlled domains and executed only on the client side, bypassing traditional server‑side security controls. Future operational patterns likely involve continuous exploitation of newly discovered Magento CVEs or other CMS flaws to expand the victim footprint while refining browser fingerprint profiles for more sophisticated fraud or credential‑exfiltration campaigns.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Healthcare
Pharmaceutical
Education
Information technology
Manufacturing
Retail
Maritime
Think tank
Entertainment
Gaming
Chemical
Hospitality
Transportation
Nuclear
Construction
Food agriculture
Legal services
Mining

Targeted Countries / Regions

US
CN
GB
KR
IN
JP
DE
RU
FR
CA
IR
SA
IL
TW
TR
AU
PK
KZ
ES
BR
SG
NL
IT
UA
PL
BY
VN
IQ
RO
MX
AE
AZ
SY
KP
LB
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

ScreamedJungle is a sophisticated threat actor that exploits publicly disclosed Magento CVEs (CVE‑2024‑34102 and CVE‑2024‑20720) to inject malicious JavaScript into e‑commerce sites. The injected code harvests detailed browser fingerprints from visitors and covertly exfiltrates this data to a Bablosoft back‑end, enabling large‑scale credential harvesting and later exploitation. Over 115 sites have been compromised globally, evidencing an opportunistic, high‑volume data‑collection campaign.

Goals & Targeting

The actor’s strategic goal is efficient collection and exploitation of unique user data, primarily via browser fingerprint harvesting. This facilitates large‑scale credential stuffing against high-value accounts on e‑commerce, banking, and governmental platforms. By targeting globally distributed Magento sites, ScreamedJungle maximises exposure while maintaining low operational risk. Their targeting hierarchy spans a broad spectrum—government, defense, finance, telecom, energy, media, healthcare, and more—indicating a flexible threat model that adapts to varying asset values. The widespread geographic reach (US, CN, GB, KR, IN, JP, DE, RU, FR, CA, IR, others) suggests the actor seeks diverse personal data pools to amplify social engineering or account takeover successes.

Enhanced Description

Key Capabilities

  • Inject malicious JavaScript into Magento e-commerce sites
  • Exploit CVE‑2024‑34102 and CVE‑2024‑20720 for site compromise
  • Perform drive‑by compromise via injected scripts
  • Collect extensive browser fingerprint data from visitors
  • Transmit fingerprints to a Bablosoft back‑end using signed POST requests
  • Use Bablosoft BrowserAutomationStudio suite (Basic Automation Suite) for automation
  • Employ FingerprintSwitcher module for client‑side redirection/credential stuffing
  • Host malicious code on controlled domains and use redirects for delivery
  • Leverage PerfectCanvas technology for pixel‑perfect fingerprint replication

MITRE ATT&CK Tactics

Initial Access
Discovery
Command and Control
Execution
Collection

ATT&CK Techniques

T1059.007
T1119
T1189
T1588.005
T1190
T1071.001
T1082

Software / Tooling

Bablosoft BrowserAutomationStudio
Basic Automation Suite (BAS)
clientsafe.js
FingerprintSwitcher
CustomServers
openbullet

Campaigns & Victims

ScreamedJungle’s operations display rapid, opportunistic exploitation of known CMS vulnerabilities to create a geographically diverse attack surface. The actor deploys the same JavaScript payload on over 115 sites simultaneously, harvesting browser fingerprints at scale while maintaining stealth through HTML comment obfuscation and controlled domain delivery. Monitoring indicates monthly fingerprint volumes of several hundred thousand individuals, predominantly from Italian markets, with prospects for expanding to other regions as more Magento installations are compromised. The campaign’s tempo is measured by the speed of CVE exploitation and the volume of exfiltrated data, suggesting a semi‑annual refresh of tactics rather than continuous daily campaigns.

IOC Patterns

  • Malicious domain URLs such as busz.io
  • Hidden JavaScript in HTML comments
  • Exploits of Magento CVEs (CVE-2024-34102, CVE-2024-20720)
  • Client-side browser fingerprint collection scripts
  • Outbound HTTP(S) POST to bablosoft back‑end for data exfiltration
  • Public key authentication usage in fingerprinting requests
  • Malicious JavaScript files served from custom domains

Recommended Actions

  • Patch or upgrade Magento installations to supported versions
  • Block traffic to known malicious domains such as busz.io
  • Inspect and sanitize third‑party scripts on e‑commerce sites
  • Deploy a Web Application Firewall with rules for unauthorized script injection
  • Monitor outbound HTTP(S) POSTs to customfingerprints.bablosoft.com
  • Educate site admins about signs of drive‑by compromise and client‑side payloads
  • Implement browser security controls (CSP, Subresource Integrity)
  • Enable logging and alerts for unexpected JavaScript injection

Suggested Tags

browser fingerprinting
web-based attack
Magento vulnerabilities
CVE-2024-34102
CVE-2024-20720
APT28
ScreamedJungle
Bablosoft BrowserAutomationStudio
CustomServers
Web Exploitation
JavaScript Injection
Client‑Side Fingerprinting
Credential Stuffing
Magento Vulnerability

Confidence Assessment

The analysis is based on observable indicators from injected JavaScript samples, CVE exploitation data, and associated tool references. While the technical evidence strongly supports a coordinated fingerprint‑harvesting campaign, attribution certainty remains low due to limited contextual signals linking the actor to a specific nation or group. Key informational gaps include the full extent of compromised sites, long‑term operational patterns beyond the current CVE window, and evidence that links ScreamedJungle to other known threat groups.

ATT&CK Techniques

Collection
1 technique
Command & Control
1 technique
Execution
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 SHA-256 Hash 1 URL 7 Filename 2

References

  1. chintangurjar.com — Cited by web research for: cpyy
  2. thehackernews.com — Cited by web research for: CosmicSting
  3. www.group-ib.com — Cited by web research for: T1588.005
  4. hxxps://screamedjungle.com/clientsafe.js — Cited by AI analysis.
  5. hxxps://customfingerprints.bablosoft.com/save — Cited by AI analysis.
  6. https://urlscan.io/responses/dcc1122bcf60d91acae0703de18ed4ac027f6d3d55eebd1e87c4f4647b2daeca/ — Cited by AI analysis.

Intel Summary

7

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
Vulnerability Exploitation
E-commerce
Financial Fraud
browser fingerprinting
web-based attack
Magento vulnerabilities
CVE-2024-34102
CVE-2024-20720
APT28
ScreamedJungle
Bablosoft BrowserAutomationStudio
CustomServers
Web Exploitation
JavaScript Injection
Client‑Side Fingerprinting
Credential Stuffing
Magento Vulnerability

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.