Bad Opsec: xcazanova -> thetoxichydra -> utoxic

Utoxic is very likely xcazanova, or at minimum very close to him based on the evidence I will show. A leopard don’t change its spots.
Spoofed 404s

Should you trust the HTTP response code when analyzing access logs for suspicious traffic?
MAGECART GROUP 12: toolser.pw skimmer

This PHP code injection is used to selectively inject the JavaScript skimmer that is loaded from
toolser.pw
(recently had been using pathc.space
).
wss://hotjar[.]info skimmer
![wss://hotjar[.]info skimmer](https://lukeleal.com/research/hotjar1.jpg)
A twist on the old ‘analytics code’ camouflage used by some skimmers to evade detection.
WordPress Injection Exfiltrates Admin Login

wp-login.php injection silently exfiltrates a victim’s username and password back to the attacker’s server.