logo

The Invisible Proxy: NGINX Hijacked for Silent SEO Poisoning

ID: a70909d1-c0a9-50b8-851e-1cf67ed8ec28

STIX ID: report--a70909d1-c0a9-50b8-851e-1cf67ed8ec28

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Datadog research describes an active campaign that compromises NGINX installations and panels (notably Baota) to inject malicious configuration directives which silently proxy user requests to attacker-controlled servers; the operation uses multi-stage shell scripts, targets specific TLDs (e.g., .in, .id, .th) and sectors (education, government), and exfiltrates infection data to a listed C2 IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.