TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
Apple Prepares a New Games App for WWDC
Opera Neon: The AI Browser That Works While You Sleep
US Now Orders Chrome Users to Update by June 5 Amid Hack Threat
Claude Gets a Voice as Anthropic Adds Hands-Free Chat Option
ChatGPT as Your New Login Key: OpenAI Expands Beyond AI Chat
Thursday, May 29, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Dragon Rank
The Tech Basic > News > Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign
News

Chinese Hackers Exploit Windows Servers in a Dangerous SEO Poisoning Campaign

Emeka Victor
Last updated: 12 September 2024 20:14
Emeka Victor
Share
SHARE

Hackers are launching a wave of attacks on Windows servers, compromising vulnerable websites and using them to steal credentials, deploy malware, and more. A newly uncovered hacking group is taking advantage of weaknesses in web application services to gain control of these servers, as revealed by a report from Cisco Talos, a cybersecurity research group. Their latest target? Websites using popular services like phpMyAdmin and WordPress.

Contents
Compromising Vulnerable ServersDragonRank Targets Various SectorsThe DragonRank Group

Compromising Vulnerable Servers

The hackers, who have been under observation by Cisco Talos for some time, begin by identifying vulnerable web services. Once they find an opening, they deploy a web shell (a malicious script that grants them access to the server). With this access, they can collect system information, deploy additional malware such as PlugX and BadIIS, or run infostealers like Mimikatz and GodPotato.

One of the key tactics employed by this group is SEO poisoning. They manipulate search engine algorithms to push compromised websites higher up in the rankings, increasing traffic to these infected pages. This strategy boosts the chances of unsuspecting users visiting the sites, thereby increasing the number of victims.

image

DragonRank Targets Various Sectors

The group’s activities, dubbed “DragonRank” by researchers, have predominantly targeted organizations in Asia, although some victims have been identified in Europe. The countries affected so far include Thailand, India, Korea, Belgium, the Netherlands, and China. Victims span a wide array of industries, from jewelry and media to healthcare, manufacturing, and even niche sectors like feng shui.

According to the report from Cisco Talos, DragonRank doesn’t seem to discriminate in its targeting. The goal appears to be the compromise of as many organizations as possible, regardless of industry. So far, more than 35 IIS (Internet Information Services) servers have been compromised, and these servers were found to be infected with BadIIS malware, a dangerous backdoor that has been active since 2020. This malware is particularly hard to detect, thanks to its advanced stealth techniques.

The DragonRank Group

Researchers suspect that the group behind DragonRank is of Chinese origin, given their use of commercial websites, a business model, and instant messaging accounts. With such an infrastructure in place, the group appears to be well-organized and intent on causing widespread damage.TechRadar first reported this growing threat, warning organizations to be vigilant in protecting their web servers. The malware deployed in these attacks is highly advanced, with BadIIS specifically designed to bypass security measures and grant unauthorized access to compromised servers. As the DragonRank campaign continues to evolve, organizations must remain vigilant to avoid becoming the next victim of this indiscriminate cyber-attack.

Read Also

Apple
Apple Prepares a New Games App for WWDC
Opera Neon: The AI Browser That Works While You Sleep
US Now Orders Chrome Users to Update by June 5 Amid Hack Threat
Claude Gets a Voice as Anthropic Adds Hands-Free Chat Option
ChatGPT as Your New Login Key: OpenAI Expands Beyond AI Chat

TAGGED:AppleGoogleSamsung
Share This Article
Facebook Reddit Copy Link Print
Share
Emeka Victor
By Emeka Victor
Follow:
Emeka Victor is a tech writer and journalist who loves exploring cultures and food. He tells exciting stories about technology and how it affects people. Making tech news simple and interesting for everyone to understand.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Apple

Apple Makes iPhone Payments Easier for Small Businesses in Europe

S.Dyema Zandria
Windows

Windows Server 2022 emergency update fixes VM freezes

S.Dyema Zandria
Google Gemini

Google Gemini to Simplify Text Selection with New Drag-and-Share Feature

S.Dyema Zandria
Google

Google’s TSMC Deal Ensures Better Pixel Chips Through 2029

S.Dyema Zandria

You Might Also Like

Apple
News

Apple’s Solarium UI Redesign for iOS 19 macOS 16 to Debut at WWDC 2025

Google
News

Google now adds ads to AI Mode and AI Overviews in search

Apple
News

Apple Delays AI Smart Screens Until Siri Upgrade Arrives in 2026

Samsung
News

Samsung Shifts to Glass Interposers by 2028 for Faster Cheaper AI Chips

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Meta AI Will Learn from Your Public Content Unless You Opt Out
Play Pitfall and MechWarrior on Game Pass’s New Retro Library
Meta Under Fire as Scam Ads Flood Facebook and Instagram
Google Veo 3 AI Videos Now Speak Realistic Sound Sets New Standard
Trump Ramps Up Trade War with EU and Apple Warning

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?