The Invisible Proxy: NGINX Hijacked for Silent SEO Poisoning
ID: a70909d1-c0a9-50b8-851e-1cf67ed8ec28
STIX ID: report--a70909d1-c0a9-50b8-851e-1cf67ed8ec28
Feed Name: securityonline.info
Threat Score
Datadog research describes an active campaign that compromises NGINX installations and panels (notably Baota) to inject malicious configuration directives which silently proxy user requests to attacker-controlled servers; the operation uses multi-stage shell scripts, targets specific TLDs (e.g., .in, .id, .th) and sectors (education, government), and exfiltrates infection data to a listed C2 IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
