logo

Defaced Websites Leading To Dokta Chef Exploit Kit

ID: 3519be3b-b785-5fae-8528-f8fe8add60a7

STIX ID: report--3519be3b-b785-5fae-8528-f8fe8add60a7

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Multiple websites were defaced by a group claiming to be AnonGhostTeam and were found hosting a highly obfuscated "lulz.htm" page that redirected visitors to the Dokta Chef exploit kit, which attempted to deliver a remote code execution exploit for CVE-2014-6332 targeting 32-bit Internet Explorer on Windows; Zscaler observed numerous compromised sites, documented indicators and protections have been deployed, and the final payload was not reachable at the time of analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.