logo

Popular Media Sites Involved In Mass Compromise

ID: eb8c3a47-6451-5238-b42b-4759bef773cd

STIX ID: report--eb8c3a47-6451-5238-b42b-4759bef773cd

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler identified a mass compromise of numerous legitimate websites (including WTOP and Federal News Radio) where attackers injected obfuscated JavaScript that conditionally (based on the browser User-Agent for Internet Explorer) loads iFrames from dynamic DNS hosts; victims are redirected to pages that deliver Fake AntiVirus scams and the ZeroAccess Trojan. The report includes example deobfuscated code, URL patterns hosted on DynDNS (e.g., myftp.biz, hopto.org), a list of compromised sites, and MD5 hashes for observed payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.