Web hosting company GoDaddyhas reported a security breach in which unknown hackers managed to steal a piece of source code, install malware on its servers, and compromise cPanel shared hosting environment – gaining access to the company’s network for several years.
The company discovered the breach after customers reported (December 2022) that their websites were being used to redirect to random domains.
See also: Fuser-master: Puts WordPress Sites at Risk

The company believes the attack is part of a complex, multi-year campaign by a group of threat actors, and that the attackers installed malware on its servers and obtained pieces of source code related to some of GoDaddy’s services.
Previous breaches in November 2021 and March 2020 are also linked to this campaign.
In the November 2021 incident, attackers compromised GoDaddy’s WordPress web hosting (hosting environment) using an exposed password, resulting in a sizable data breach that affected 1.2 million Managed WordPress.
Following the March 2020 breach, GoDaddy alerted 28,000 customers that a threat actor used their web hosting account credentials in October 2019 to log into their hosting account via SSH (Secure Shell).
GoDaddy is currently working with cybersecurity forensics experts and law enforcement agencies around the world to investigate the root cause of the breach.
The company has found some evidence linking the threat actors to a broader campaign that has targeted other web hosting companies worldwide in recent years.
The apparent goal of the attackers is to infect websites and servers with malware for phishing campaigns, malware distribution, and other malicious activities.
See also: Cyberattack on FBI computer network

GoDaddy is one of the largest domain registrars overwith, 20 million customers worldwide using its services.
This breach highlights how important it is for companies to implement strong security measures when it comes to protecting themselves, as well as the need for customers themselves to regularly change their passwords and take extra steps to protect their online accounts.
Information source: bleepingcomputer.com
