logo

GroupGreeting e-card site attacked in “zqxq” campaign 

ID: 06417a0a-fff1-5f83-b611-790eb4f007df

STIX ID: report--06417a0a-fff1-5f83-b611-790eb4f007df

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-01-09

Date Updated: 2026-04-28

...
...

Malwarebytes uncovered a widespread JavaScript-injection campaign called "zqxq" that infected GroupGreeting.com and thousands of other high-traffic sites; the obfuscated script performs token generation, environment checks, and remote payload retrieval to redirect visitors to phishing pages or secondary malware, mirroring NDSW/NDSX (TDS Parrot) traffic-distribution behavior and exploiting outdated CMS/plugins and seasonal traffic spikes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.