HomeSecurityUniversity sites using MediaWiki and TWiki hacked to spread Fortnite...

University sites using MediaWiki and TWiki hacked to spread Fortnite spams

US university websites using MediaWiki and TWiki have been hacked to spread Fortnite spams.

See also: Lazarus hackers: Linked to 3CX attack and targeting Linux users with fake job offers

University sites using MediaWiki and TWiki hacked to spread Fortnite spams

Researchers noticed that Wiki pages and documentation hosted by universities such as Stanford, MIT, Berkeley, UMass Amherst, Northeastern, Caltech, among others, had been compromised.

BleepingComputer confirmed that the malicious campaign was live and had targeted additional school websites, including that of the University of Michigan.

See also: Capita: Confirmed that recent cyberattack led to a data breach

Malicious campaign compromises university wiki sites

This week, Twitter user g0njxa identified over a dozen sub-domains belonging to prominent US universities serving Fortnite spam.

These sites appear to run either TWiki or MediaWiki – the latter being a Content Management System (CMS) platform that powers Wikipedia and many Wikimedia sites.

Fortnite

These wiki pages, supposedly uploaded by spammers, lure readers into visiting fake websites that claim to offer "free gift cards," "Fortnite Bucks," and cheats, among other digital artifacts.

These domains, however, load fake Fortnite pages that are essentially phishing forms that ask users for their credentials .

University sites using MediaWiki and TWiki hacked to spread Fortnite spams

In other cases, BleepingComputer observed that the sites in question promised users gift cards in exchange for completing fake surveys.

Fortnite

Europa's Europass was also abused

Although the malicious campaign primarily targeted university websites built with MediaWiki, it appears that some government websites were also affected by the same threat actors.

These included mini-websites hosted by a Brazilian government, as well as the European Union.

Specifically, in the case of Europa.eu, it appears that spammers are abusing the Europass e-Portfolio service — a job search portal that allows prospective European residents to create and upload their CVs and cover letters as PDFs:

Fortnite

It remains unclear which exploits threat actors are leveraging to upload spam pages and PDF documents to websites belonging to legitimate organizations.

Last month, MediaWiki released security updates that patched multiple vulnerabilities in the platform - however, none of them appeared to be directly related to the ongoing malicious campaign.

See also: In 2023, Ukraine was the target of 60% of Russian phishing attacks

BleepingComputer continues to investigate the cause of the problem.

MediaWiki and TWiki sysadmins should scan their websites for spam and malicious content, especially for resources containing keywords like 'gift card', 'Fortnite', etc.

Users should avoid clicking suspicious links on compromised Wiki pages.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS