logo

BESCOM users being redirected to RIG EK

ID: fa27f1f6-cc68-57a9-a288-94b2cc320d49

STIX ID: report--fa27f1f6-cc68-57a9-a288-94b2cc320d49

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ discovered on 11 September 2017 that the BESCOM bill payment page was compromised with malicious meta-refresh redirects to a RIG exploit kit landing page (188.225.82.40) and subsequent cryptocurrency scam sites/YouTube content; the RIG landing page served obfuscated JavaScript and a Flash fingerprinting component that attempted to download a malware payload (which failed), IoCs are provided and BESCOM was notified and apparently remediated the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.