GrelosGTM group abuses Google Tag Manager to attack e-commerce websites
Reported 15 Sep 2026 by otx · Severity: medium
A cybercriminal group dubbed GrelosGTM has been exploiting Google Tag Manager's legitimate functionality to compromise e-commerce websites. First detected in early April 2020, the group evolved their tactics by February 2021 to inject malicious Google Tag Manager scripts into tar