logo

Dead-end job: ResumeLooters infect websites in APAC through SQL injection and XSS attacks

ID: 1943bbb2-6fd8-529d-8cac-1d7070e031e4

STIX ID: report--1943bbb2-6fd8-529d-8cac-1d7070e031e4

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2024-02-06

Date Updated: 2026-04-27

...
...

The provided Markdown contains a malicious JavaScript payload that detects specific target hostnames, exfiltrates cookies (via a POST to https://admin.cloudnetsofe.com/...), and injects a full-screen iframe (XSS-style overlay) to affected pages. It includes timing/limit logic to control repeated execution and references multiple target domains (redacted) indicating a multi-site campaign; portions of the code for beaconing/notification and additional data exfiltration are present or commented out.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.