Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » 150,000 sites compromised by JavaScript injection by promoting Chinese gambling platforms
Global Security

150,000 sites compromised by JavaScript injection by promoting Chinese gambling platforms

AdminBy AdminMarch 27, 2025No Comments3 Mins Read
Chinese Gambling Platforms
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 27, 2025Red LakshmananMalicious software / safety site

Chinese gambling platforms

A campaign that penetrates legitimate sites with malicious JavaScript injections to promote Chinese gambling is continued, and approximately 150,000 sites are compromised.

“The actor threatened a little updated his interface, but still relies on IFRAME injection to show a full-screen circulation in the visitors’ browser,” C/Side Security Analyst Himanshu Anand – Note In a new analysis.

As of writing, there is More than 135 800 sites containing a useful load of JavaScript, according to Publicww statistics.

Cybersecurity

As documented Last month, the company’s security company includes infection with angry JavaScript sites, which is designed to kidnap the user’s browser to redirect site visitors to pages that promote gambling platforms.

The redirection has been found through JavaScript, located on five different domains (for example, “Zuizhongyj (.) Com”), which in turn serve the main useful load responsible for the recharge.

C/Side said there is also another company that entails injection scenarios and IFRAME elements in HTML, which represents legal rates such as Bet365 using official logos and branding.

The ultimate goal is to serve a full -screen lining using CSS, which causes malicious gambling when visiting one of the infected sites instead of the real web -based website.

“This attack demonstrates how the threat subjects are constantly adapting, increasing their reach and using new layers of exacerbation,” Anand said. “Such attacks on the clients are increasing and more and more results every day.”

The disclosure of information occurs when Godaddy has revealed details about the long -term surgery on malicious programs called Dollyway World Damination, which threatens more than 20,000 sites in the world since 2016. As of February 2025, more than 10,000 unique WordPress sites were victims of this scheme.

Chinese gambling platforms
Chinese gambling platforms

“The current iteration (…) is primarily focused on visitors of the infected WordPress via the retained redirect scripts that use the distributed network of the traffic direction (TDS) located on the impaired web -styities,” – Note.

“These scripts are redirected by site visitors to different pages of scam through road networks related to VextrioOne of the largest well -known networking networks that use sophisticated DNS methods, traffic distribution systems and domain generation algorithms to deliver malicious programs and scams on global networks. “

The attacks begin with the introduction of a dynamically generated scenario to the WordPress site, eventually redirecting visitors to Vextrio or Lospollos links. The lesson is also said to have used advertising networks as Screw to monetize traffic from broken sites.

Cybersecurity

Malicious injections on the server side are facilitated through the PHP code, inserted into the active plugins, and take measures to disable security plugins, removal of malicious administrator users and legitimate administrator powers to achieve their goals.

Since then, Godaddy has shown that Dollyway TDS has been using a distributed WordPress websites as TDS and Command-Control (C2), reaching 9-10 million monthly impressions. Except Litigation Traffic network.

Approximately in November 2024, as they say, Dollyway operators removed several C2/TDS servers, with the TDS scenario received URL -url from a telegram called Trafferredirect.

“Dollyway’s relationship violation with Lospolos means a significant turning point in this perennial company” Synegubko noted. “While the operators demonstrated a significant adaptation, quickly passing the alternative methods of monetization of the road, rapid changes in infrastructure and partial shutdown indicate a certain level of operational impact.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.