Also known as: APT28, Pawn Storm, Fancy Bear, tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, MiniDionis, Chinastrats, CosmicSting, Sednit, TG-0110, Newscaster, Hammertoss, Patchwork, CVE-2024-20720
ScreamedJungle has emerged as a stealthy adversary that leverages known weaknesses in Magento e‑commerce platforms to gain unauthorised control of target websites. By executing drive‑by compromise via injected JavaScript hidden within HTML comment tags, the actor collects exhaustive browser fingerprint data from each site visitor and sends it to a secure Bablosoft server using cryptographically signed POST requests. The campaign relies on automated tools such as the Bablosoft BrowserAutomationStudio suite (Basic Automation Suite) and the FingerprintSwitcher module. PerfectCanvas technology is employed for pixel‑perfect replication of user fingerprints, ensuring high fidelity data for targeted exploitation. The actor’s modus operandi mirrors other large‑scale phishing and credential‑stuffing operations, hinting at a broader espionage agenda. ScreamedJungle has targeted over 115 Magento installations across multiple continents, harvesting hundreds of thousands of user fingerprints each month (e.g., an estimated 200,000 Italian fingerprints per month). The technique is notable for its low detectability: scripts are served from controlled domains and executed only on the client side, bypassing traditional server‑side security controls. Future operational patterns likely involve continuous exploitation of newly discovered Magento CVEs or other CMS flaws to expand the victim footprint while refining browser fingerprint profiles for more sophisticated fraud or credential‑exfiltration campaigns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ScreamedJungle is a sophisticated threat actor that exploits publicly disclosed Magento CVEs (CVE‑2024‑34102 and CVE‑2024‑20720) to inject malicious JavaScript into e‑commerce sites. The injected code harvests detailed browser fingerprints from visitors and covertly exfiltrates this data to a Bablosoft back‑end, enabling large‑scale credential harvesting and later exploitation. Over 115 sites have been compromised globally, evidencing an opportunistic, high‑volume data‑collection campaign.
Goals & Targeting
The actor’s strategic goal is efficient collection and exploitation of unique user data, primarily via browser fingerprint harvesting. This facilitates large‑scale credential stuffing against high-value accounts on e‑commerce, banking, and governmental platforms. By targeting globally distributed Magento sites, ScreamedJungle maximises exposure while maintaining low operational risk. Their targeting hierarchy spans a broad spectrum—government, defense, finance, telecom, energy, media, healthcare, and more—indicating a flexible threat model that adapts to varying asset values. The widespread geographic reach (US, CN, GB, KR, IN, JP, DE, RU, FR, CA, IR, others) suggests the actor seeks diverse personal data pools to amplify social engineering or account takeover successes.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ScreamedJungle’s operations display rapid, opportunistic exploitation of known CMS vulnerabilities to create a geographically diverse attack surface. The actor deploys the same JavaScript payload on over 115 sites simultaneously, harvesting browser fingerprints at scale while maintaining stealth through HTML comment obfuscation and controlled domain delivery. Monitoring indicates monthly fingerprint volumes of several hundred thousand individuals, predominantly from Italian markets, with prospects for expanding to other regions as more Magento installations are compromised. The campaign’s tempo is measured by the speed of CVE exploitation and the volume of exfiltrated data, suggesting a semi‑annual refresh of tactics rather than continuous daily campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on observable indicators from injected JavaScript samples, CVE exploitation data, and associated tool references. While the technical evidence strongly supports a coordinated fingerprint‑harvesting campaign, attribution certainty remains low due to limited contextual signals linking the actor to a specific nation or group. Key informational gaps include the full extent of compromised sites, long‑term operational patterns beyond the current CVE window, and evidence that links ScreamedJungle to other known threat groups.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics