Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Python-based bots that use PHP servers help spread the gambling platform
Global Security

Python-based bots that use PHP servers help spread the gambling platform

AdminBy AdminJanuary 17, 2025No Comments3 Mins Read
PHP Servers
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 17, 2025Ravi LakshmananWeb Security / Botnet

PHP servers

Cybersecurity researchers have uncovered a new campaign targeting web servers running PHP-based applications to promote gambling platforms in Indonesia.

“The past two months have seen a significant number of attacks by Python-based bots, suggesting a coordinated effort to exploit thousands of web applications,” Imperva researcher Daniel Johnston said in the analysis. “These attacks appear to be related to the proliferation of gambling-related sites, potentially in response to increased government control.”

The Thales-owned company said it discovered millions of requests originating from a Python client containing a command to install GSocket (aka Global Socket), an open source tool that can be used to establish a communication channel between two machines regardless of the network perimeter.

Cyber ​​security

It should be noted that GSocket was used in the many a cryptojacking operation in recent months, not to mention using the access provided by the utility to inject malicious JavaScript code into sites for steal payment information.

Attack chains in particular include attempts to deploy GSocket using pre-existing web shells installed on already compromised servers. Most attacks have been found to single out servers running a popular learning management system (LMS) called Moodle.

A noteworthy aspect of the attacks are the additions to bashrc and crontab system files to ensure that GSocket is active even after the webshell is removed.

The access granted by GSocket to these target servers was determined to deliver PHP files containing HTML content linking to online gambling services specifically targeting Indonesian users.

“At the top of each PHP file was PHP code designed so that only search robots could access the page, but normal site visitors would be redirected to another domain” Johnston said. “The purpose of this is to target users who are looking for well-known gambling services and then redirect them to another domain.”

Imperva said the redirects lead to “pktoto(.)ss”, a well-known Indonesian gambling site.

Cyber ​​security

Development is underway as c/side revealed a widespread malware campaign that targets more than 5,000 sites worldwide to create unauthorized administrator accounts, install a malicious plugin from a remote server, and transfer credentials to it.

The exact initial access vector used to deploy the JavaScript malware on these sites is currently unknown. The malware was codenamed WP3.XYZ due to the domain name associated with the server used to obtain the plugin and steal data (“wp3(.)xyz”).

To reduce the attack, it is recommended that WordPress site owners update their plugins, block the fake domain with a firewall, look for suspicious admin accounts or plugins and remove them.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.