logo

Abuse of hidden “well-known” directory in HTTPS sites

ID: 0014eeb4-4bd0-5e81-9285-c8d3651920f6

STIX ID: report--0014eeb4-4bd0-5e81-9285-c8d3651920f6

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabZ detected hundreds of compromised WordPress and Joomla sites that attackers are abusing the .well-known ACME/pki-validation directories to host and persist malicious content: obfuscated HTML/JavaScript redirectors and ZIPs lead to a packed Shade/Troldesh ransomware binary (delivered via JS and ZIP attachments) that drops a Tor client, registers persistence, and encrypts files using AES-256 and RSA; the report includes infection-chain analysis, artifacts (registry keys, filenames, ransom notes), telemetry on phishing vs. ransomware distribution, and an extensive list of IOCs for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.