HomeSecurity42,000 websites tricked users into thinking they were legitimate

42,000 websites tricked users into thinking they were legitimate

A profit-making malicious group known as “Fangxiao” has created a large network consisting of over 42,000 web domains. These domains copy well-known brands and redirect users to websites promoting adware or dating sites. In some cases, these groups also offer “free” gifts.

See also: Scam: Blackmailers target site owners and threaten to leak data
websites

The fake domains are used for a massive scheme that generates advertising revenue for Fangxiao's websites or more clients who purchase traffic from the group.

A traffic generation system is a plan or system designed to increase traffic to a website. Traffic generation systems can be used for both personal and business websites. However, they can also be used by malicious actors to generate profit, as in this case.

The China-based threat actors, according to a detailed report by Cyjax, have been active since 2017, spoofing over 400 well-known brands from across sectors.

The report provides examples of well-known companies, such as Coca-Cola, McDonald’s, Knorr, Unilever, Shopee, Emirates and others. Many of these fake websites feature multiple language options to appear more authentic.

See also: 42 "pirate" sites with sports content were removed

Most often, people who fall victim to Fangxiao are redirected to websites that infect them with the Trojan or other malware. However, Fangxiao's connection to the administrators of these websites has not been verified.

sectors

Fangxiao creates nearly 300 new imitation domains for clients and herself every day to generate significant traffic.

The operators maliciously used at least 24,000 search domains since early March 2022 to promote their fake prizes.

The full list of domains used by Cyjax in this campaign is below.

Cyjax's investigation led to several key findings that suggest Fangxiao is a Chinese operator, such as the use of Mandarin on one of the exposed control panels.

See also: Hackers managed to introduce SocGholish malware into hundreds of news sites

However, apart from some email addresses indicating they are linked to hacking like OGUsers, there is no further information on who the threat actors may be.

Furthermore, we do not know whether the perpetrators behind this large-scale baiting scheme that uses numerous fake websites to attract victims are collaborating with the final destination websites or whether Fangxiao is simply benefiting from being an intermediary.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS