HomeSecurityThe cPanels of compromised sites are sought after in cybercrime markets

Hacked site cPanels are sought after in cybercrime markets

Cybercriminals openly advertise access to hacked websites as part of the underground economy. One of the most promising products is compromised cPanel credentials. They are sold by the thousands in fraudulent chat groups at commodity prices and promoted as plug-and-play infrastructure for phishing and fraud campaigns.

See also: Grubhub confirms data breach 

cPanel

In new research, Flare security researchers analyzed activity in monitored rogue groups over a seven-day period, showing a structured ecosystem operating at scale.

They analyzed more than 200,000 posts mentioning cPanel access, explaining how cPanel has become sought after, why it is desired by cybercriminals, and how it fits into the overall threat landscape.

cPanel is one of the most widely used Linux-based web hosting control panels in the world. It provides a structured layer of management above standard system services, acting as an orchestration and automation interface for managing hosting accounts, domains, email services, databases, DNS zones, SSL certificates, and file systems.

According to Shodan, there are over 1.5 million servers connected to the internet running cPanel software. The heat map shows how cPanel is popular primarily in the US (over 1 million results).

See also: Iranian Cyber ​​Front: Increased activity by hacktivists

Hacked site cPanels are sought after in cybercrime markets

Once a cybercriminal obtains the legitimate credentials to access the administration level of a website, a wide range of possibilities are activated:

  • Developing backdoors for retention
  • Create new administrative users for maintenance
  • Gaining root access to the server
  • Deploying a phishing kit as a subdomain under the legitimate domain name
  • Creating SMTP accounts under the domain to spread phishing or spam campaigns
  • Theft and extraction of invaluable data (PII, secrets) from databases

In shared hosting environments, a single cPanel can allow access to dozens of domains, and at an organizational level, it can compromise the entire web presence. Because attackers use valid credentials, traditional security checks may not immediately flag the activity or may miss it entirely. Abuse can begin with quiet outbound email or hidden file uploads before the visible exploit is detected.

Flare monitors underground Telegram channels where cybercriminals sell compromised cPanel credentials, SMTP access, and hosting infrastructure, providing alerts when domains, hosting accounts, or credentials appear in bulk sales before they are exploited.

See also: SloppyLemming targets critical infrastructure in Pakistan and Bangladesh

Hacked site cPanels are sought after in cybercrime markets

Historically, cybercriminals have gained access to cPanel environments through a mix of credential abuse, web application compromise, and server-level exploitation. The most common method has been stolen or brute-forced credentials. Attackers are exploiting phishing campaigns, password reuse from data breaches, credential stuffing, and automated brute-force attacks against exposed cPanel login portals.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS