Threat Intelligence, Network Security

Illicit NGINX configurations harnessed for web traffic hijacking

Hackers linked to the exploitation of the React2Shell vulnerability have tapped malicious NGINX configurations to divert web traffic from Asian top-level domains, government and educational TLDs, and Chinese hosting infrastructure to attacker-controlled infrastructure, The Hacker News reports.

Illicit configurations have been injected into NGINX via shell scripts included in a multi-stage toolkit for persistence and the creation of more configuration files for web traffic hijacking, according to an analysis from Datadog Security Labs. Aside from shell scripts serving as an orchestrator for later attack stage execution and targeting the Baota Management Panel, the toolkit also features shell scripts enumerating typical NGINX configuration locations, prioritizing Linux or containerized NGINX configurations, and reporting all active NGINX traffic hijacking rules.

Such findings come as 56% of React2Shell exploitation attempts two months after the flaw's disclosure were noted by GreyNoise to have stemmed from just a pair of IP addresses. While one of the IP addresses enables cryptomining binary retrieval from staging servers, the other facilitates direct reverse shell opening to the scanner IP, said GreyNoise researchers.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds