Tag: Web Traffic Hijacking Campaign

Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign
News

Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign

Details of an ongoing web traffic hijacking campaign that has targeted NGINX installations and management panels such as Baota (BT) in an effort to redirect the traffic through the attacker's infrastructure have been made public by cybersecurity experts. Threat actors linked to the latest React2Shell (CVE-2025-55182, CVSS score: 10.0) exploitation were seen employing malicious NGINX configurations to carry out the attack, according to Datadog Security Labs. According to security researcher Ryan Simon, the malicious configuration intercepts normal web communication between users and websites and redirects it through backend servers under the control of the attacker. Asian TLDs (.in,.id,.pe,.bd,.th), Chinese hosting infrastructure (Baota Panel), and government and educational TLDs (.e...