Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Dragonrank exploits IIS servers with malicious Badiis software for SEO fraud and gambling
Global Security

Dragonrank exploits IIS servers with malicious Badiis software for SEO fraud and gambling

AdminBy AdminFebruary 10, 2025No Comments3 Mins Read
BadIIS Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 10, 2025Red LakshmananMalicious software / web security

Badus malicious software

The actors of the threat were observed on the orientation on the Internet information server (IIS) in Asia as part of a manipulation campaign to optimize search engines (SEO) intended for installing malware Badiis.

“It is likely that the company is financially motivated since the redirection of users to illegal gambling sites that indicate that attackers deploy Badiis for profit,” – Trend Micro Researchers Ted Lee and Lenart Bermejj – Note In an analysis published last week,

The goals of the company include IIS servers in India, Thailand, Vietnam, Philippines, Singapore, Taiwan, South Korea, Japan and Brazil. These servers are connected with government, universities, technology companies and telecommunications sectors.

Cybersecurity

Requests for compromised servers can be submitted by changed content from the attackers, ranging from redirect to gambling sites to connecting to rogue, which place malicious software or credentials.

Suspected that activity is the work of a Chinese group of threats known as Dragonwhich was recorded by Cisco Talos last year as providing malicious Badiis software through SEO manipulation schemes.

It is said that the company Dragonrank, in turn, is related to the subject called Group 9 According to ESET in 2021, it compromised IIS servers for proxy and SEO fraud.

SEO fraud and gambling are redirected

Trend Micro, however, noted that the revealed malware artifacts have similarities to the option used by group 11, which presents two different modes for SEO fraud and the introduction of the suspicious JavaScript code in response to legal visitors’ requests.

“Installed Badiis can change the information about the HTTP headline requested from the web server,” the researchers said. “It checks the”-Agent user “and” referer “in the http header.”

“If these fields contain certain search portals or keywords, Badiis redirects the user to the online gambling page instead of the legitimate web page.”

Cybersecurity

Development occurs when Silent Push linked the Chinese content delivery network (CDN) with practice that calls infrastructure laundering, which actors threaten IP addresses from major hosting providers such as Amazon Web Services (AWS) and Microsoft Azure and use them Criminal sites.

It is said that the fun lease is over 1,200 IPS at Amazon and almost 200 IPS with Microsoft, which have been shot since. Malicious infrastructure called Triad NexusRetail phishing schemes, Romanesque scams and money laundering operations were found to be fuel through fake gambling.

“But new IPS is constantly purchased every few weeks”, the company – Note. “The rainbow probably uses fraudulent or stolen accounts to purchase these IPS to display your Cname.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.