Researchers reported a Gootkit-linked web malware campaign that compromised websites by appending malicious iframe redirects to site files and sending visitors to attacker-controlled domains generated by a date-based domain generation algorithm (DGA). The infrastructure used domains made of 16 pseudo-random letters, first on .ru with the parameter sid=botnet2, then on waw.pl with sid=botnet_api2, indicating an evolution in the campaign’s redirect chain and backend tracking.
A more advanced variant encrypted the entire infected JavaScript file, concealing both legitimate and malicious code and making remediation harder because decryption depended on the victim site’s origin domain. The activity was tied to the label gootkit in malware comments, and researchers said the infections were likely spread through a Plesk Panel vulnerability, prompting recommendations to patch Plesk and rotate FTP, SFTP, and SSH credentials; the observed malicious domains resolved to the same IP address and later appeared suspended for abuse, though that status may not have been consistently presented to all visitors.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky published analysis of a web malware campaign associated with the name "gootkit" that injects malicious iframes into website files and uses a date-based domain generation algorithm to rotate redirect domains. The report also described a newer variant that encrypts entire infected JavaScript files and assessed that infections most likely spread via a recent Plesk Panel vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.