logo

Hackers compromise NGINX servers to redirect user traffic

ID: 24f9bcc1-0540-55a8-b8fa-2f3482445a11

STIX ID: report--24f9bcc1-0540-55a8-b8fa-2f3482445a11

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-02-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

DataDog researchers disclosed a stealthy campaign that compromises NGINX installations and Baota hosting panels to inject malicious configuration 'location' blocks that rewrite and proxy selected URL paths to attacker-controlled domains while preserving headers; a five-stage script toolkit (zx.sh, bt.sh, 4zdh.sh, zdh.sh, ok.sh) performs targeted discovery, safe configuration modification, validation, reloads, and exfiltration to C2 158.94.210.227, primarily targeting Asian TLDs and government/education sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.