logo

Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious

ID: ceedf194-9a02-53dd-a641-1e58726f4043

STIX ID: report--ceedf194-9a02-53dd-a641-1e58726f4043

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-27

...
...

Datadog Security Research details an active campaign that injects malicious NGINX configuration using automated shell scripts to intercept and proxy legitimate web traffic through attacker-controlled backends; targets include Baota (BT) panel installations and specific TLDs (.in, .id, .pe, .bd, .th, .edu, .gov), with IOCs such as xzz.pier46.com, ide.hashbank8.com, th.cogicpt.org and C2 IP 158.94.210.227, plus recommended detection rules and observable behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.