Chinese hackers target Windows servers with SEO poisoning campaign

Hackers are exploiting vulnerable servers to take over websites to steal people’s login credentials, spread malware, and more.

A report from Cisco Talos, who have been tracking the activity for a while, revealed that the group first looked for vulnerable web application services such as phpMyAdmin, WordPress or the like. They then used the vulnerabilities to implement a web shell that gave them control over the server.