logo

Millions at Risk As 'Parrot' Web Server Compromises Take Flight

ID: 0675f7ac-6184-5c57-8475-51e25c0a013f

STIX ID: report--0675f7ac-6184-5c57-8475-51e25c0a013f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-23

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 researchers describe Parrot TDS, an active traffic distribution system that has been compromising thousands of websites since 2021 to inject malicious JavaScript that profiles visitors and redirects them to malware (notably FakeUpdates/SocGholish). The report catalogs payload variants (V1–V9), evasion/obfuscation tactics, IoCs (including ~100 SHA256 hashes and keywords like "ndsx", "ndsw", "ndsj"), likely exploitation of CMS/server vulnerabilities, and recommended mitigations such as server audits, keyword searches for injected files, URL filtering, and next‑generation firewalls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.