GroupGreeting e-card site attacked in “zqxq” campaign
ID: 06417a0a-fff1-5f83-b611-790eb4f007df
STIX ID: report--06417a0a-fff1-5f83-b611-790eb4f007df
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes uncovered a widespread JavaScript-injection campaign called "zqxq" that infected GroupGreeting.com and thousands of other high-traffic sites; the obfuscated script performs token generation, environment checks, and remote payload retrieval to redirect visitors to phishing pages or secondary malware, mirroring NDSW/NDSX (TDS Parrot) traffic-distribution behavior and exploiting outdated CMS/plugins and seasonal traffic spikes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
