HomeSecurityDragonRank Black Hat SEO Malicious Gang Targets IIS Servers

DragonRank Black Hat SEO Malicious Gang Targets IIS Servers

The new DragonRank Black Hat malware gang appears to be manipulating search engine rankings (SEO) targeting Asia and Europe.

Black Hat SEO

This malicious gang has left its mark in countries such as Thailand, India, Korea, Belgium, the Netherlands and China.

"DragonRank exploits the target application's web services to deploy a web shell and uses it to collect system information and launch malware such as PlugX and BadIIS, running various credential harvesting utilities," said security researcher Joey Chen.

Read more: The reappearance of FAREIT malware is a critical threat

The attacks targeting the deployment of the BadIIS malware, which was first documented by ESET in August 2021, resulted in the compromise of 35 Internet Information Services (IIS) servers.

It is specifically designed to facilitate the use of proxy software and SEO fraud, by turning a compromised IIS server into a relay node for malicious communications between its clients, i.e. other threat actors, and their victims.

In addition, it can modify the content displayed in search engines (SEO) to deceive algorithms and boost the ranking of websites that are of interest to hackers.

“One of the most striking aspects of the research is the flexibility of IIS malware and the detection of criminal SEO, where malware abuses it to manipulate search engine algorithms and improve the reputation of third-party websites,” researcher Zuzana Hromcova told Hacker News at the time.

The latest set of attacks identified by Cisco Talos spans a wide range of industry sectors, including jewelry, media, research services, healthcare, video and television production, construction, transportation, religious and spiritual organizations, IT services, international affairs, agriculture, sports, and even feng shui.

See more: Are you a programmer? Beware! Lazarus hacking gang uses fake coding tests to distribute malware

The attack chains begin by exploiting known vulnerabilities in web applications, such as phpMyAdmin and WordPress, to inject the open source ASPXspy. This tool acts as a conduit for adding additional tools to the targets' environment.

The main goal of the campaign is to compromise IIS servers hosting corporate websites to inject the BadIIS malware. They intend to use them as launching points for scams, leveraging keywords related to porn and sex.

Another important aspect of the malware is its ability to disguise itself as a Google in the User-Agent string when relaying the connection to the server , allowing it to bypass certain website security measures.

“The threat engages in SEO manipulation, altering or exploiting search engine algorithms to improve a website’s ranking in search results,” Chen explained. “They carry out these attacks with the aim of directing traffic to malicious websites, increasing the visibility of malicious content, or disrupting competitors.”.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A major way in which DragonRank stands out from other Black Hat cybercrime groups is its attempt to compromise additional servers within the target’s network and maintain control over them. This is achieved through PlugX, a backdoor widely used by Chinese threat actors, as well as various credential such as Mimikatz, PrintNotifyPotato, BadPotato, and GodPotato.

Although the PlugX malware used in attacks relies on DLL side-loading techniques, the DLL responsible for launching the encrypted payload exploits the Windows Structured Exception Handling (SEH) mechanism. This mechanism helps the legitimate file (i.e. the vulnerable DLL) load PlugX without being detected.

DragonRank Black Hat

Evidence discovered by Cisco Talos shows that the malicious gang maintains a presence on Telegram under the alias “tttseo” and uses the instant messaging app QQ to facilitate illicit business transactions with customers.

Read also: Mustang Panda uses PUBLOAD and HIUPAN malware in attacks

“These hackers also offer supposedly high-quality customer service, tailoring promotion strategies to best meet their customers’ needs,” Chen said. “Customers are able to submit keywords and websites they wish to promote, and DragonRank develops strategies that meet those specifications. In addition, the gang is skilled at targeting promotions to specific countries and languages, ensuring a personalized and comprehensive approach to online marketing.”

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS