- May 4, 2019
- 826
The threat actors gained access to the website using legitimate credentials for the FTP endpoint used for managing the web application. In some cases, the passwords used by the attackers were strong and were unlikely to have been included in a dictionary for a brute-force attack.
Hundreds of thousands of websites hacked as part of redirection campaign
Thousands of Websites Hijacked Using Compromised FTP Credentials Researchers reported that threat actors compromised thousands of websites using legitimate FTP credentials to hijack traffic. Cybersecurity firm Wiz reported that since early September 2022, threat actors compromised tens of...
securityaffairs.com