Web hosting company GoDaddy discloses a security breach in which the threat actors have stolen source code and installed malware on its servers in a long-running attack.
The threat actors have breached its cPanel shared hosting environment. GoDaddy states that it is unable to determine the timing of the initial compromise. They are investigating the breach to determine the root cause of the incident.
The malware installed on the systems of the company was intermittently redirecting random customer websites to malicious sites.
The security breach was discovered in December 2022 when customers reported that their sites were being used to redirect to random domains.
The company believes that this incident was carried out by a sophisticated and organized group targeting hosting services. The hackers aim to infect websites and servers with malware for phishing campaigns, malware distribution and other malicious activities. However, they stated that the attacks have not impacted their business or operations.
The attack is part of a multi-year campaign that was the cause of the data breaches disclosed in November 2021, which impacted 1.2 million customers, and March 2020, which exposed data of 28,000 customers.
The company announced that it will continue to invest to secure its infrastructure, but warns that threat actors are becoming even more aggressive and sophisticated and that current geopolitical situation is worsening the situation.















Comments