Skip to main content

Multi-year malware attack at godaddy.com

  • February 18, 2023
  • 4 comments
  • 41 views

JMeixner
Forum|alt.badge.img+16

A sever malware attack was discovered at godaddy.com - the worlds fourth biggest domain registrar.

Seems that there was sourcecode and customer data stolen, malware was installed on the servers. Customers websites were redirected to malicious websites.

The whole campaign lasted several years.

https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/

 

 

4 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • February 18, 2023

Read about this one pretty serious. I had moved away from them years ago.


HunterLAFR
Forum|alt.badge.img+9
  • Veeam Legend
  • February 18, 2023

Wow, this is so scary, and also so true!

thanks for sharing 


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • February 19, 2023

….”the attackers had access to the company's network for multiple years”. This piece of information right here is scary! 

 

 


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • February 20, 2023

An attack at this level sounds horrible. There's nothing you could do to defend yourself, when your hosted environment is attacked from the inside or Name records are being changed.

The company says that previous breaches disclosed in November 2021 and March 2020 are also linked to this multi-year campaign.

Probably the bigger a companies infrastructure is, the better can a threat actor hide itself. At a certain point you can't trust your environment anymore and should start with a fresh setup. But at that size this is probably impossible.