Skip to content
DnsLister Forum

Where domain hunters compare notes

Wild actual case: Hacker used Cloudflare to steal Google traffic and drop malware on users

​

Man, I gotta admit, seeing this real case over on the Cloudflare sub just made me so mad. Someone's site getting hijacked like that is an absolute nightmare.

What actually went down there is pretty wild. Even though the guy formatted his PC and changed his passwords, the hacker was already chillin inside his Cloudflare account. They stole his session tokens way back during that first malware infection, so they didn't even need his new password or 2FA to get in. Once they got access to the dashboard, they just set up a stealthy redirect rule to send Google visitors straight to a fake captcha scam. That trap basically tricks poor everyday users into running nasty PowerShell commands on their own machines.

So yeah, the site files themselves weren't even touched, the attacker just hijacked the DNS traffic layer using old stolen access. It is super sneaky, kinda scary, and definitely a tough lesson on revoking active sessions right away.

https://i.redd.it/9j7w1mpph0rh1.jpeg

Source: r/StopBadBots · by /u/siterightaway

Leave a Reply

Your email address will not be published. Required fields are marked *