backdoror-web-shells

Over 4,000 backdoors hijacked by registering expired domains

Teilen:

Over 4,000 abandoned but still active web backdoors were hijacked and their communication infrastructure sinkholed after researchers registered expired domains used for commanding them.

Some of the live malware (web shells) was deployed on web servers of  high-profile targets, including government and university systems, ready to execute commands from anyone who took control of the communication domains.

Together with The Shadowserver Foundation, researchers at offensive security outfit WatchTowr Labs prevented these domains and the corresponding victims from falling into the hands of malicious actors.

Finding thousands of breached systems

Backdoors are malicious tools or code planted on a compromised system to allow unauthorized remote access and control. Threat actors typically use them for persistent access and to execute on the compromised system commands that would further the attack.

WatchTowr researchers started hunting for domains in various web shells and purchased any that had expired, essentially taking control of the backdoors.

After setting up a logging system, the abandoned but still active malware started sending requests that allowed the researchers to identify at least some of the victims.

From registering more than 40 domains, the researchers received communication from over 4,000 compromised systems attempting to “phone home.”

<img class=”i-amphtml-blurry-placeholder” src=”data:;base64,Sample from the registered domains
Sample of registered domains
Source: WatchTowr

The researchers found several backdoor types, including the “classic” r57shell, the more advanced c99shell, which offers file management and brute-forcing capabilities, and the ‘China Chopper’ web shell that is often linked to APT groups.

The report even mentions one backdoor that showcased behavior associated with the Lazarus Group, although it later clarifies that it was likely a reuse of the threat actor’s tool by others.

Among the varied set of breached machines, WatchTowr found multiple systems within China’s government infrastructure, including courts, a compromised Nigerian government judicial system, and systems in Bangladesh’s government network.

In addition, infected systems were found in educational institutions in Thailand, China, and South Korea.

WatchTowr handed over the responsibility of managing the hijacked domains to The Shadowserver Foundation to ensure that they will not become available for takeover in the future. Shadowserver is now sink-holing all traffic sent from breached systems to its domains.

WatchTowr’s research, although not complex, shows that expired domains from malware operations could still serve new cybercriminals, who would also get some victims by simply registering the control domains.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:52 am, Mai 19, 2025
Wetter-Symbol 10°C
L: 10° | H: 11°
broken clouds
Luftfeuchtigkeit: 84 %
Druck: 1020 mb
Wind: 5 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
10° | 11°°C 0 mm 0% 11 mph 84 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
10° | 11°°C 0 mm 0% 6 mph 84 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
12° | 15°°C 0 mm 0% 7 mph 75 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 9 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 11 mph 40 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,276.09
-0.12%
Ethereum(ETH)
€2,129.32
-4.13%
Fesseln(USDT)
€0.89
-0.01%
XRP(XRP)
€2.10
-0.89%
Solana(SOL)
€147.33
-1.79%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.196382
1.50%
Shiba Inu(SHIB)
€0.000013
-0.41%
Pepe(PEPE)
€0.000012
4.30%
Peanut das Eichhörnchen(PNUT)
€0.285018
5.43%
Nach oben scrollen