Researchers reported that Parrot TDS has compromised thousands of websites—primarily servers running WordPress, Joomla, and other CMS platforms—and injected malicious JavaScript that profiles visitors and selectively redirects them to follow-on payloads. Palo Alto Networks said the campaign likely began as early as 2019, earlier than previous public reporting, and has persisted through multiple script revisions with heavier obfuscation while keeping the same basic attack chain. The operation relies on landing scripts commonly tagged with identifiers such as ndsj or ndsw, which fingerprint browsers, evade analysis, and fetch second-stage payload scripts often marked ndsx from attacker-controlled infrastructure.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
Unit 42 published research concluding that Parrot TDS had been active as early as 2019, revising the campaign timeline earlier than prior public reporting. The report detailed persistent use of ndsj, ndsw, and ndsx-tagged JavaScript across evolving landing and payload scripts.
Unit 42 analyzed more than 10,000 Parrot TDS landing scripts collected from August 2019 through October 2023 and identified four major landing-script versions plus nine payload-script versions. The research found the attack chain remained broadly consistent despite increasing obfuscation.
Unit 42 observed that since August 2022, more Parrot TDS landing scripts were injected as multiple lines rather than a single appended line. Researchers assessed this was likely an evasion technique.
Avast published research describing Parrot TDS as a newly identified traffic direction system infecting more than 16,500 websites, primarily poorly secured WordPress and Joomla servers. The report also documented FakeUpdate/SocGholish as the most prevalent downstream campaign and noted a malicious PHP backdoor in the proxied variant.
Between March 1 and March 29, 2022, Avast protected more than 600,000 unique users from visiting infected Parrot TDS sites. Brazil, India, and the United States were among the most affected countries in that period.
Avast identified increased Parrot TDS activity in February 2022 after detecting suspicious JavaScript files on compromised web servers. The campaign was using tens of thousands of compromised websites to redirect visitors into malicious campaigns.
Avast assessed that Parrot TDS had likely been active since October 2021 based on first samples and C2 domain registration dates. This was the earlier public understanding before later research pushed the start date back to 2019.
A Group-IB blog post about Prometheus TDS was published, indicating public reporting on that traffic distribution system by this date. The provided content does not include further event details from the article itself.
Unit 42 found that full Parrot TDS samples were available by August 2019, providing an explicit early anchor for the campaign's presence in the wild.
Unit 42 reported that Parrot TDS samples first appeared as early as 2019, earlier than prior public reporting that placed the campaign's start in 2021. Full Parrot TDS samples were available by August 2019.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcedecoded.avast.io
Open sourcebleepingcomputer.com
Open sourceblog.group-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.