US university websites using MediaWiki and TWiki have been hacked to spread Fortnite spams.
See also: Lazarus hackers: Linked to 3CX attack and targeting Linux users with fake job offers

Researchers noticed that Wiki pages and documentation hosted by universities such as Stanford, MIT, Berkeley, UMass Amherst, Northeastern, Caltech, among others, had been compromised.
BleepingComputer confirmed that the malicious campaign was live and had targeted additional school websites, including that of the University of Michigan.
See also: Capita: Confirmed that recent cyberattack led to a data breach
Malicious campaign compromises university wiki sites
This week, Twitter user g0njxa identified over a dozen sub-domains belonging to prominent US universities serving Fortnite spam.
These sites appear to run either TWiki or MediaWiki – the latter being a Content Management System (CMS) platform that powers Wikipedia and many Wikimedia sites.

These wiki pages, supposedly uploaded by spammers, lure readers into visiting fake websites that claim to offer "free gift cards," "Fortnite Bucks," and cheats, among other digital artifacts.
These domains, however, load fake Fortnite pages that are essentially phishing forms that ask users for their credentials .

In other cases, BleepingComputer observed that the sites in question promised users gift cards in exchange for completing fake surveys.

Europa's Europass was also abused
Although the malicious campaign primarily targeted university websites built with MediaWiki, it appears that some government websites were also affected by the same threat actors.
These included mini-websites hosted by a Brazilian government, as well as the European Union.
Specifically, in the case of Europa.eu, it appears that spammers are abusing the Europass e-Portfolio service — a job search portal that allows prospective European residents to create and upload their CVs and cover letters as PDFs:

It remains unclear which exploits threat actors are leveraging to upload spam pages and PDF documents to websites belonging to legitimate organizations.
Last month, MediaWiki released security updates that patched multiple vulnerabilities in the platform - however, none of them appeared to be directly related to the ongoing malicious campaign.
See also: In 2023, Ukraine was the target of 60% of Russian phishing attacks
BleepingComputer continues to investigate the cause of the problem.
MediaWiki and TWiki sysadmins should scan their websites for spam and malicious content, especially for resources containing keywords like 'gift card', 'Fortnite', etc.
Users should avoid clicking suspicious links on compromised Wiki pages.
Information source: bleepingcomputer.com
