Malicious web redirect scripts stealth up to hide on hacked sites
ID: 6869e35b-a261-569b-a235-fc812cc7a26c
STIX ID: report--6869e35b-a261-569b-a235-fc812cc7a26c
Feed Name: Bleeping Computer
Unit 42 analysis shows the Parrot TDS is an active, large-scale malicious redirect campaign that has infected many WordPress and Joomla sites (Avast observed ~16,500), using evolving, increasingly obfuscated JavaScript landing and payload scripts to profile visitors and redirect targeted users to phishing pages or malware; the report details script versions, obfuscation techniques, payload variants, and IoCs such as the ndsj/ndsw/ndsx keywords, and advises owners to search for rogue PHP files, scan for those keywords, and use web application protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
