comdak's User Avatar

@comdak

in /hacking 10 days ago

Hackers compromise NGINX servers to redirect user traffic

Hackers compromise NGINX servers to redirect user traffic - Featured Image

Hackers compromise NGINX servers to redirect user traffic

www.bleepingcomputer.com - faviconbleepingcomputer.com
TLDR

A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker's backend infrastructure. The malicious campaign targets NGINX installations and Baota hosting management panels used by sites with Asian top-level domains and government and educational sites. Attackers modify existing NGINX configuration files to capture incoming requests and forward traffic to attacker-controlled domains.

12Score: 12

2 Comments