logo

Redirection Roulette: Thousands of hijacked websites in East Asia redirecting visitors to other sites

ID: 5103dc12-e317-51c1-abe4-b64781e23573

STIX ID: report--5103dc12-e317-51c1-abe4-b64781e23573

Feed Name: Wiz Blog

Threat Score
65/100

Date Published: 2023-03-02

Date Updated: 2026-05-01

...
...

Since September 2022, an unknown actor has compromised a large number of websites (conservatively estimated ≥10,000) — mostly aimed at East Asian audiences — by using stolen or otherwise acquired FTP credentials to inject obfuscated JavaScript that fingerprints visitors and conditionally redirects them (via geofenced, Cloudflare-fronted infrastructure and intermediate redirectors) to adult and gambling sites; the report includes IOCs, script analysis, honeypot evidence (attacker IP 172.81.104.64), possible ties to Pagoda/BT Panel infections, and remediation advice (rotate credentials, switch to FTPS/SFTP, restore clean assets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.