Dead-end job: ResumeLooters infect websites in APAC through SQL injection and XSS attacks
ID: 1943bbb2-6fd8-529d-8cac-1d7070e031e4
STIX ID: report--1943bbb2-6fd8-529d-8cac-1d7070e031e4
Feed Name: Group-IB Blog
The provided Markdown contains a malicious JavaScript payload that detects specific target hostnames, exfiltrates cookies (via a POST to https://admin.cloudnetsofe.com/...), and injects a full-screen iframe (XSS-style overlay) to affected pages. It includes timing/limit logic to control repeated execution and references multiple target domains (redacted) indicating a multi-site campaign; portions of the code for beaconing/notification and additional data exfiltration are present or commented out.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
