Injecting Malicious HTML IFrames – Still A Popular Attack Vector
ID: c8dea3b7-03e3-5d1d-8aaf-3f7e4a49347d
STIX ID: report--c8dea3b7-03e3-5d1d-8aaf-3f7e4a49347d
Feed Name: Zscaler Security Research Blog
Threat Score
A widespread web compromise was observed where attackers injected malicious IFrames into many legitimate sites (search results indicate ~85k infected pages). The injections, likely achieved via SQL injection and persistent XSS in forums and dynamic pages, redirect users to malicious .ru domains (a list of IFrame URLs is provided) and have triggered Google warnings for some affected pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
