Tag Archive for: redirect

Malicious web redirect service infects 16,500 sites to push malware


Malicious web redirect service infects 16,500 sites to push malware

A new traffic direction system (TDS) called Parrot is relying on servers that host 16,500 websites of universities, local governments, adult content platforms, and personal blogs.

Parrot’s use is for malicious campaigns to redirect potential victims matching a specific profile (location, language, operating system, browser) to online resources such as phishing and malware-dropping sites.

Threat actors running malicious campaigns buy TDS services to filter incoming traffic and send it to a final destination serving malicious content.

TDS are also legitimately used by advertisers and marketers, and some of these services were exploited in the past to facilitate malspam campaigns.

Used for RAT distribution

Parrot TDS was discovered by threat analysts at Avast, who report that it’s currently used for a campaign called FakeUpdate, which delivers remote access trojans (RATs) via fake browser update notices.

Site displaying the fake browser update notice
Site displaying the fake browser update warning (Avast)

The campaign appears to have started in February 2022 but signs of Parrot activity have been traced as far back as October 2021.

“One of the main things that distinguishes Parrot TDS from other TDS is how widespread it is and how many potential victims it has,” comments Avast in the report

“The compromised websites we found appear to have nothing in common apart from servers hosting poorly secured CMS sites, like WordPress sites.”

Malicious JavaScript code seen in compromised sites
Malicious JavaScript code seen in compromised sites (Avast)

Threat actors have planted a malicious web shell on compromised servers and copied it to various locations under similar names that follow a “parroting” pattern.

Moreover, the adversaries use a PHP backdoor script that extracts client information and forwards requests to the Parrot TDS command and control (C2) server.

In some cases, the operators use a shortcut without the PHP script, sending the request directly to the Parrot infrastructure.

Parrot's direct and proxied forwarding
Parrot’s direct and proxied forwarding (Avast)

Avast says that in March 2022 alone its services protected more than 600,000 of its clients from visiting these infected sites, indicating the massive scale of the Parrot redirection gateway.

Most of the users targeted by these…

Source…

Concerned About the Bing Redirect Virus? Here’s 2 Ways to Remove the Malware From Your PC


The Bing redirect virus can be annoying and dangerous, as it leads you to specific websites and bombard you with advertisements. It is, however, not to be confused with Bing.com– a legitimate search engine backed by a legitimate and reliable company.

Find out more about the Bing redirect virus and how you can remove it from your computer.

What Is the Bing Redirect Virus?

Bing Redirect is technically not a virus, Trend Micro said, more so a precursor to what could be the virus.

It is also worth mentioning that this virus is not related to Bing.com. On that note, the site can be promoted by various browser hijacking potentially unwanted applications, Malware Remove said.

These applications do not require the users’ explicit approval to infiltrate in and once the installation is confirmed, it could already trigger unwanted changes to the browsers’ settings. A very annoying feature of the virus is how it can deliver intrusive online advertisements.

When victims get redirected to this particular search engine continuously, it significantly diminishes the internet browsing experience. The browser hijackers can also inject different helper objects to stop victims from returning to the previous browser setting options, making it virtually impossible to return to such settings unless the malicious software is removed.

The hijackers can use the recorded data and can result in serious privacy issues of identity theft, Malware Remove pointed out.

Read Also: Global Fraud Protection – Exposing Online Scams

2 Ways to Remove Bing Redirect Virus From Your PC

Browser hijackers can often make their way to your device by using deceptive bundling methods, stealthily installing third-party apps with regular software, Malware Remove explained. Hiding in plain sight, a lot of users may not pay attention to what they are downloading or installing and proceed to install the apps, leading to the inadvertent installation of the harmful apps,…

Source…

751 Domains Hijacked to Redirect Traffic to Exploit Kits – BleepingComputer

751 Domains Hijacked to Redirect Traffic to Exploit Kits
BleepingComputer
The domain hijacking event also broke incoming HTTPS traffic to the affected domains. Following the incident, Gandi reset all passwords for all the accounts it uses to manage TLD entries at country and domain-specific registrars. Last week, a security …

HTTPS hijacking – read more