Mpack Attacks Originate From Porn Sites

LOS ANGELES — A wave of cyber attacks said to be originating from several hundred pornography websites has exposed surfers to the notorious Mpack hacker toolkit. The attacks were launched from a network of more than 10,000 compromised domains, according to Computer World.

Mpack, developed by Russian hackers, is a collection of exploits that compromises the security of infected PCs. Close to 200 porn domain names have been hacked to redirect to servers hosting Mpack. The attacks were said to have begun June 17.

“The pornographic sites, which tend to specialize on incestuous content, have an obfuscated I-Frame code appended at the end of the HTML code,” Ryan Flores said on the Trend Micro blog. “This I-Frame redirects to another domain that will serve a script file to download a copy of TROJ_AGENT.QMN. Right now, we are not sure whether the porn sites are compromised to host the I-Frames, are created to do so, or are being paid to host the I-Frames.”

Symantec security analyst Amado Hidalgo told Computer World that he believes the “Mpack gang appears to be using an I-Frame manager tool to automate the task on a large scale,” which is how the hackers were able to infect so many sites in a short time. This manager tool is successful because it injects the malicious I-Frame code to the sites’ HTML that redirects surfers to the Mpack server.

“It takes as input a list of website administrator accounts, possibly obtained in the black market,” Hidalgo said. These accounts are logged into the manager tool, which enables previously purged sites to become re-infected.

“A simple cleanup of the page is not sufficient,” Hidalgo said. “The site administrator’s credentials need to be changed.”

Mpack was created by a hacker who goes by the name $ash. The toolkit sells for around $1,000.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

More Conservative Organizations Distance Themselves From Anti-Porn Project 2025

A growing list of conservative groups which had formerly endorsed Project 2025 — which calls for the total criminalization of adult content production and distribution — have reportedly distanced themselves from the blueprint, following Donald Trump’s claims that he disagrees with an unspecified number of its positions.

BranditScan Unveils Protection Plan for Adult Studios

BranditScan has launched a new content protection plan tailored specifically for adult studios.

CAM4 Debuts Weekly 'Skyy Knox's CAM Crawl' Livestream

CAM4 is launching "Skyy Knox’s CAM Crawl," a new livestream running every Sunday at 3 p.m. PDT.

Texas Judge Pauses AG Ken Paxton's Aylo Lawsuit Until SCOTUS Decision

A Texas district judge granted a request Wednesday to pause proceedings in the lawsuit filed by Attorney General Ken Paxton against Aylo over Pornhub’s alleged failure to implement Texas’ controversial age verification requirements, pending the outcome of the Free Speech Coalition-led lawsuit against Paxton, which will be heard by the Supreme Court during the next term.

Author of UN Report Recommending Worldwide Criminalization of Sex Work, Porn to Speak at NCOSE Summit

Jordanian activist Reem Alsalem, a special rapporteur on violence against women and girls at the United Nations Human Rights Council who recently issued a controversial report recommending that governments abolish all forms of sex work, including porn, will speak at anti-porn lobby NCOSE’s 2024 summit in August.

Spicey AI Voice Chat Platform Launches

Spicey AI, a platform that uses artificial intelligence to create interactive voice messages from chatbots based on adult performers, has launched.

Utherverse to Host 8th Annual VirtualCon in September

Virtual reality and metaverse technology company Utherverse will hold the eighth edition of its annual virtual conference, VirtualCon, from Sept. 26-28.

Pornhub Shuts Down Access in Nebraska Over Age Verification

Aylo began blocking access to Pornhub in Nebraska on Monday, in anticipation of the state’s new age verification law — one of many such bills promoted by religious conservatives around the country — which is scheduled to go into effect Thursday.

FeelMe AI Launches 3 New Subscription Tiers

FeelMe AI has launched three new subscription levels, allowing users to connect compatible Kiiroo sex toys to their videos for interactive solo play.

CamSoda Launches AI Girlfriend Builder

CamSoda has debuted a personalized "AI girlfriend" feature, which allows users to create their very own virtual companion at no charge, including free NSFW role-play and chat.

Show More