Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious
Datadog documents an active campaign hijacking web traffic via tampered NGINX configs and compromised Baota management panels — with IOCs to check against your own reverse-proxy infrastructure.
Summary written by editorial AI · Source link below
Datadog Security Research has identified an active web traffic hijacking campaign that targets NGINX installations and management panels like Baota (BT). In this post, we provide our analysis of the techniques this campaign uses and share indicators of compromise you can check for in your NGINX configurations.
Editorial Analysis
NGINX serves as the reverse proxy for a large share of European web applications; configuration-level compromise is stealthy and can persist through standard OS-level security scans.
Audit your NGINX configurations and management panel access for the published IOCs, and implement file-integrity monitoring on reverse-proxy config files.
Attackers are silently hijacking web traffic by modifying server configurations — a risk that standard endpoint security may not detect.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Datadog Security Labs in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d