HomeSecurityMalicious scripts are hiding in hacked websites

Malicious scripts are hiding in hacked websites

Security researchers observed over 10,000 malicious scripts used by the Parrot traffic direction system (TDS) and discovered optimizations that make the malicious code more invisible to security mechanisms.

See also: New JavaScript malware targets banks worldwide

Malicious scripts

Parrot TDS was discovered by cybersecurity firm Avast in April 2022 and is believed to have been active since 2019, forming part of a campaign that attacks vulnerable WordPress and Joomla websites with JavaScript that redirects users to a malicious site.

When analyzed by Avast researchers, it emerged that Parrot had infected at least 16,500 websites, signaling a massive operation.

The actors behind Parrot sell the traffic to malicious actors, who use it on users visiting infected websites to identify and redirect relevant targets to malicious destinations, such as phishing pages or malware delivery sites.

A recent report from Palo Alto Networks' Unit 42 team presents findings that suggest that Parrot TDS is still very active, and its creators continue to work to make its presence in JavaScript more difficult to detect and remove.

Unit 42 analyzed 10,000 Parrot scripts collected from August 2019 to October 2023. Researchers discovered four different versions that show an advancement in the use of obfuscation techniques.

Parrot scripts help analyze user profiles and force the victim's browser to load a script bundle from the server , which performs the redirect.

According to the researchers, the scripts used in Parrot TDS campaigns are identified by specific keywords in the code, such as 'ndsj,' 'ndsw,' and 'ndsx.'

See also: The NPM ecosystem is at risk from “Manifest Confusion” attacks

The Unit 42 team observed that most infections in the sample examined have migrated to the most recent version of the script, making up 75% of the total, with 18% using the previous version and the remainder running older scripts.

websites

The fourth version of the landing script introduced the following improvements compared to earlier versions:

  • Improved obfuscation with complex code structure and encoding mechanisms.
  • The various indicators and measures that impair pattern recognition and signature-based detection.
  • Differentiation in the treatment of strings and numbers, including their formatting, encoding, and processing.

Despite the additional layers of obfuscation and changes to the code structure, the core functionality of the V4 script remains consistent with previous versions.

Regarding the payload scripts, which are responsible for executing user redirects, Unit 42 discovered nine different variants. These are almost identical, except for minor forms of obfuscation and checks of the operating system target performed by some of them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Overall, Parrot TDS remains an active and evolving threat that is gradually becoming more sophisticated.

See also: CISA: Provides recovery script for victims of ESXiArgs ransomware
What are the methods of protection against malicious redirect scripts?

One of the most effective methods of protection is to keep your software updated. Malicious redirect scripts often exploit vulnerabilities in older versions of software, so it is vital to keep software up to date.

Using robust security software can also provide protection against malicious redirect scripts. This software can detect and remove malicious scripts before they can cause damage.

Additionally, learning and implementing best practices for security can be very helpful. This can include avoiding clicking on suspicious links and using strong passwords.

Finally, using a virtual private network (VPN) can provide additional protection. A VPN can hide your real IP address, making it harder for malicious redirect scripts to work.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS