TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
Adobe’s Latest Camera App Brings Smart Photography to Your iPhone
How to Use Siri with ChatGPT for Instant AI Help via Apple Intelligence
Punch-Hole Camera, Under-Screen Face ID Still Expected With iPhone 18 Pro
Microsoft Password Deletion: Act Now Before August Deadline
Facebook Messenger Passkey Login: iOS Android Security
Friday, Jun 20, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Dragon Rank
The Tech Basic > News > Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign
News

Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign

Emeka Victor
Last updated: 12 September 2024 20:14
Emeka Victor
Share
SHARE

Hackers are launching a wave of attacks on Windows servers, compromising vulnerable websites and using them to steal credentials, deploy malware, and more. A newly uncovered hacking group is taking advantage of weaknesses in web application services to gain control of these servers, as revealed by a report from Cisco Talos, a cybersecurity research group. Their latest target? Websites using popular services like phpMyAdmin and WordPress.

Contents
Compromising Vulnerable ServersDragonRank Targets Various SectorsThe DragonRank Group

Compromising Vulnerable Servers

The hackers, who have been under observation by Cisco Talos for some time, begin by identifying vulnerable web services. Once they find an opening, they deploy a web shell (a malicious script that grants them access to the server). With this access, they can collect system information, deploy additional malware such as PlugX and BadIIS, or run infostealers like Mimikatz and GodPotato.

One of the key tactics employed by this group is SEO poisoning. They manipulate search engine algorithms to push compromised websites higher up in the rankings, increasing traffic to these infected pages. This strategy boosts the chances of unsuspecting users visiting the sites, thereby increasing the number of victims.

image

DragonRank Targets Various Sectors

The group’s activities, dubbed “DragonRank” by researchers, have predominantly targeted organizations in Asia, although some victims have been identified in Europe. The countries affected so far include Thailand, India, Korea, Belgium, the Netherlands, and China. Victims span a wide array of industries, from jewelry and media to healthcare, manufacturing, and even niche sectors like feng shui.

According to the report from Cisco Talos, DragonRank doesn’t seem to discriminate in its targeting. The goal appears to be the compromise of as many organizations as possible, regardless of industry. So far, more than 35 IIS (Internet Information Services) servers have been compromised, and these servers were found to be infected with BadIIS malware, a dangerous backdoor that has been active since 2020. This malware is particularly hard to detect, thanks to its advanced stealth techniques.

The DragonRank Group

Researchers suspect that the group behind DragonRank is of Chinese origin, given their use of commercial websites, a business model, and instant messaging accounts. With such an infrastructure in place, the group appears to be well-organized and intent on causing widespread damage.TechRadar first reported this growing threat, warning organizations to be vigilant in protecting their web servers. The malware deployed in these attacks is highly advanced, with BadIIS specifically designed to bypass security measures and grant unauthorized access to compromised servers. As the DragonRank campaign continues to evolve, organizations must remain vigilant to avoid becoming the next victim of this indiscriminate cyber-attack.

Read Also

Adobe
Adobe’s Latest Camera App Brings Smart Photography to Your iPhone
How to Use Siri with ChatGPT for Instant AI Help via Apple Intelligence
Punch-Hole Camera, Under-Screen Face ID Still Expected With iPhone 18 Pro
Microsoft Password Deletion: Act Now Before August Deadline
Facebook Messenger Passkey Login: iOS Android Security

TAGGED:AppleGoogleSamsung
Share This Article
Facebook Reddit Copy Link Print
Share
Emeka Victor
By Emeka Victor
Follow:
Emeka Victor is a tech writer and journalist who loves exploring cultures and food. He tells exciting stories about technology and how it affects people. Making tech news simple and interesting for everyone to understand.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

iPhone

iPhone Fold mass production set for mid‑2026 as plans firm up

Salman Akhtar
iOS 26

iOS 26 Guide: Permanently Delete Your Instagram Account in Minutes

Salman Akhtar
Midjourney

Midjourney V1 AI Video Model Launches: Image to Video on Discord

Salman Akhtar
Spotify

Inside Spotify’s App: New Data Hints at Lossless Launch Readiness

Salman Akhtar

You Might Also Like

Google Gemini
News

Google Gemini Faces Backlash as Pokémon Panic Exposes Weaknesses

FaceTime
News

FaceTime Clear Call Guide: iOS 18 Audio and Video Mastery

iOS 26
News

Apple’s Secret iOS 26 Chatbot: How Shortcuts Expose the Truth

Exynos 2500
GadgetNews

Samsung Readies Exynos 2500 and Satellite Link for Galaxy Z Flip 7

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
OpenAI Ends Scale AI Partnership After Meta Investment Deal
YouTube Open Call Connects Brands With Creators for Campaigns
Spotify Premium Adds Remote Watch Downloads for Wear OS
Adobe Firefly Mobile Unleashes Professional AI Creativity Anywhere
How ChatGPT’s Multi-Solution AI Coder Is Reshaping Development Workflows

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?