loader image
NGINX servers redirect traffic: engineer with laptop in data center as blue and amber light ribbons split along fiber.
NGINX Servers Redirect Traffic to Attacker Domains

Threat actors are exploiting NGINX server configurations to redirect web traffic to attacker-controlled destinations in a new, covert campaign. The attackers, linked to previous React2Shell exploits, are now focusing on servers using the Baota panel, a popular management tool in Asian markets.

Rather than deploying traditional malware, they inject malicious directives into NGINX location blocks. This enables them to hijack user traffic and route it through proxy_pass commands to malicious servers. The attackers use a series of scripts—including zx.sh, bt.sh, and 4zdh.sh—to automate the process, targeting both Baota and generic Linux deployments.

Affected sites redirect unsuspecting users to scam and gambling domains. To avoid detection, they modify HTTP headers using proxy_set_header, making logs appear normal. Researchers note the campaign targets .in, .id, .th, and .bd TLDs, along with .gov and .edu domains.

Administrators should inspect config files for unauthorized directives, particularly those set to make NGINX servers redirect traffic.

Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers

Write a Reply or Comment

Your email address will not be published. Required fields are marked *