TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
DeepSeek Boosts China’s AI Race as Washington Rolls Out New Plan
Why Meta Calls EU’s New Ad Transparency Law Impossible to Follow
Why Did Google Take a Month to Act Against Firebase-Hosted Spyware?
How to Add AppleCare One to Your iPhone Upgrade Program
Apple’s Dating App Fee Showdown: Why Europe Holds All Cards
Monday, Jul 28, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Dragon Rank
The Tech Basic > News > Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign
News

Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign

Emeka Victor
Last updated: 12 September 2024 20:14
Emeka Victor
Share
SHARE

Hackers are launching a wave of attacks on Windows servers, compromising vulnerable websites and using them to steal credentials, deploy malware, and more. A newly uncovered hacking group is taking advantage of weaknesses in web application services to gain control of these servers, as revealed by a report from Cisco Talos, a cybersecurity research group. Their latest target? Websites using popular services like phpMyAdmin and WordPress.

Contents
Compromising Vulnerable ServersDragonRank Targets Various SectorsThe DragonRank Group

Compromising Vulnerable Servers

The hackers, who have been under observation by Cisco Talos for some time, begin by identifying vulnerable web services. Once they find an opening, they deploy a web shell (a malicious script that grants them access to the server). With this access, they can collect system information, deploy additional malware such as PlugX and BadIIS, or run infostealers like Mimikatz and GodPotato.

One of the key tactics employed by this group is SEO poisoning. They manipulate search engine algorithms to push compromised websites higher up in the rankings, increasing traffic to these infected pages. This strategy boosts the chances of unsuspecting users visiting the sites, thereby increasing the number of victims.

image

DragonRank Targets Various Sectors

The group’s activities, dubbed “DragonRank” by researchers, have predominantly targeted organizations in Asia, although some victims have been identified in Europe. The countries affected so far include Thailand, India, Korea, Belgium, the Netherlands, and China. Victims span a wide array of industries, from jewelry and media to healthcare, manufacturing, and even niche sectors like feng shui.

According to the report from Cisco Talos, DragonRank doesn’t seem to discriminate in its targeting. The goal appears to be the compromise of as many organizations as possible, regardless of industry. So far, more than 35 IIS (Internet Information Services) servers have been compromised, and these servers were found to be infected with BadIIS malware, a dangerous backdoor that has been active since 2020. This malware is particularly hard to detect, thanks to its advanced stealth techniques.

The DragonRank Group

Researchers suspect that the group behind DragonRank is of Chinese origin, given their use of commercial websites, a business model, and instant messaging accounts. With such an infrastructure in place, the group appears to be well-organized and intent on causing widespread damage.TechRadar first reported this growing threat, warning organizations to be vigilant in protecting their web servers. The malware deployed in these attacks is highly advanced, with BadIIS specifically designed to bypass security measures and grant unauthorized access to compromised servers. As the DragonRank campaign continues to evolve, organizations must remain vigilant to avoid becoming the next victim of this indiscriminate cyber-attack.

Read Also

Chrome OS
Google Merges Chrome OS and Android into One Unified Platform
Pokémon Go: Carnival of Love 2024 is Starting Soon – Here’s What You Need to Know
New Steam Low Price: PC Gamers Grabbing Popular Story Game
New Interface for WhatsApp Apple Users iOS 23.15.72: What are the new changes?
The Star Ability of Zelda: Tears of the Kingdom Inspires US University To Use The Nintendo Exclusive For Engineering Education

TAGGED:AppleGoogleSamsung
Share This Article
Facebook Reddit Copy Link Print
Share
Emeka Victor
By Emeka Victor
Follow:
Emeka Victor is a tech writer and journalist who loves exploring cultures and food. He tells exciting stories about technology and how it affects people. Making tech news simple and interesting for everyone to understand.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

DeepSeek

DeepSeek Boosts China’s AI Race as Washington Rolls Out New Plan

Salman Akhtar
Meta

Why Meta Calls EU’s New Ad Transparency Law Impossible to Follow

Salman Akhtar
Google

Why Did Google Take a Month to Act Against Firebase-Hosted Spyware?

Salman Akhtar
AppleCare One

How to Add AppleCare One to Your iPhone Upgrade Program

Salman Akhtar

You Might Also Like

Apple Dating App
News

Apple’s Dating App Fee Showdown: Why Europe Holds All Cards

Google Opal
News

Imagination to App: How Google Opal Democratizes AI Creation Now

App Store
News

App Store Age Ratings Overhauled: New 13+/16+/18+ Tiers

Blender
News

No Compromises: Blender Confirms Professional iPad App Is Coming

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Beyond Black and White: How Amazon’s New Kindles Make Color Reading Affordable
Beyond Chat: How GPT-5 Could Become Your AI Co-Pilot
Google AI Try-On: See Clothes on You, Not Models
PlayStation DualSense Controllers Gain Four‑Device Pairing via Simple Button Combo
Unexpected Leak Shows All Four Pixel 10 Phones and Colors

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?