Skip to main content

Multi-year malware attack at godaddy.com


JMeixner
Forum|alt.badge.img+17
  • On the path to Greatness
  • 2650 comments

A sever malware attack was discovered at godaddy.com - the worlds fourth biggest domain registrar.

Seems that there was sourcecode and customer data stolen, malware was installed on the servers. Customers websites were redirected to malicious websites.

The whole campaign lasted several years.

https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/

 

 

4 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8506 comments
  • February 18, 2023

Read about this one pretty serious. I had moved away from them years ago.


HunterLAFR
Forum|alt.badge.img+8
  • Veeam Legend
  • 422 comments
  • February 18, 2023

Wow, this is so scary, and also so true!

thanks for sharing 


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • 1394 comments
  • February 19, 2023

….”the attackers had access to the company's network for multiple years”. This piece of information right here is scary! 

 

 


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1352 comments
  • February 20, 2023

An attack at this level sounds horrible. There's nothing you could do to defend yourself, when your hosted environment is attacked from the inside or Name records are being changed.

The company says that previous breaches disclosed in November 2021 and March 2020 are also linked to this multi-year campaign.

Probably the bigger a companies infrastructure is, the better can a threat actor hide itself. At a certain point you can't trust your environment anymore and should start with a fresh setup. But at that size this is probably impossible.


Comment