Redirection Roulette: Thousands of hijacked websites in East Asia redirecting visitors to other sites
ID: 5103dc12-e317-51c1-abe4-b64781e23573
STIX ID: report--5103dc12-e317-51c1-abe4-b64781e23573
Feed Name: Wiz Blog
Since September 2022, an unknown actor has compromised a large number of websites (conservatively estimated ≥10,000) — mostly aimed at East Asian audiences — by using stolen or otherwise acquired FTP credentials to inject obfuscated JavaScript that fingerprints visitors and conditionally redirects them (via geofenced, Cloudflare-fronted infrastructure and intermediate redirectors) to adult and gambling sites; the report includes IOCs, script analysis, honeypot evidence (attacker IP 172.81.104.64), possible ties to Pagoda/BT Panel infections, and remediation advice (rotate credentials, switch to FTPS/SFTP, restore clean assets).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
