Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious
ID: ceedf194-9a02-53dd-a641-1e58726f4043
STIX ID: report--ceedf194-9a02-53dd-a641-1e58726f4043
Feed Name: Datadog Security Labs
Threat Score
Datadog Security Research details an active campaign that injects malicious NGINX configuration using automated shell scripts to intercept and proxy legitimate web traffic through attacker-controlled backends; targets include Baota (BT) panel installations and specific TLDs (.in, .id, .pe, .bd, .th, .edu, .gov), with IOCs such as xzz.pier46.com, ide.hashbank8.com, th.cogicpt.org and C2 IP 158.94.210.227, plus recommended detection rules and observable behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
