{"id":48446,"date":"2022-09-14T14:52:41","date_gmt":"2022-09-14T14:52:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/33836\/Breach-Of-Software-Maker-Used-To-Backdoor-As-Many-As-200-000-Servers.html"},"modified":"2022-09-14T14:52:41","modified_gmt":"2022-09-14T14:52:41","slug":"breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/","title":{"rendered":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers"},"content":{"rendered":"<figure class=\"intro-image intro-left\"> <img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/data-breach-800x435.jpeg\" alt=\"A cartoon man runs across a white field of ones and zeroes.\"><figcaption class=\"caption\"><\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"> <a title=\"32 posters participating\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/information-technology\/2022\/09\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">42<\/span> <span class=\"visually-hidden\"> with 32 posters participating<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p> <!-- cache hit 291:single\/related:624e60e89098806cf25b7f6841e9fb70 --><!-- empty --><\/p>\n<p>FishPig, a UK-based maker of e-commerce software used by as many as 200,000 websites, is urging customers to reinstall or update all existing program extensions after discovering a security breach of its distribution server that allowed criminals to surreptitiously backdoor customer systems.<\/p>\n<p>The unknown threat actors used their control of FishPig&#8217;s systems to carry out a supply chain attack that infected customer systems using FishPig&#8217;s fee-based Magento 2 modules with <a href=\"https:\/\/decoded.avast.io\/davidalvarez\/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild\/\">Rekoobe<\/a>, a sophisticated backdoor discovered in June. Rekoobe masquerades as a benign SMTP server and can be activated by covert commands related to handling the startTLS command from an attacker over the Internet. Once activated, Rekoobe provides a reverse shell that allows the threat actor to remotely issue commands to the infected server.<\/p>\n<p>&#8220;We are still investigating how the attacker accessed our systems and are not currently sure whether it was via a server exploit or an application exploit,&#8221; Ben Tideswell, the lead developer at FishPig, wrote in an email. &#8220;As for the attack itself, we are quite used to seeing automated exploits of applications and perhaps that is how the attackers initially gained access to our system. Once inside though, they must have taken a manual approach to select where and how to place their exploit.&#8221;<\/p>\n<p>FishPig is a seller of Magento-WordPress integrations. Magento is an open source e-commerce platform used for developing online marketplaces. The supply-chain attack only affects paid Magento 2 modules.<\/p>\n<p>Tideswell said the last software commit made to its servers that didn&#8217;t include the malicious code was made on August 6, making that the earliest possible date the breach likely occurred. Sansec, the security firm that discovered the breach and <a href=\"https:\/\/sansec.io\/research\/rekoobe-fishpig-magento\">first reported it<\/a>, said the intrusion began on or before August 19. Tideswell said FishPig has already &#8220;sent emails to everyone who has downloaded anything from FishPig.co.uk in the last 12 weeks alerting them to what&#8217;s happened.&#8221;<\/p>\n<p>In a <a href=\"https:\/\/fishpig.co.uk\/security-announcements\/#X20220913\">disclosure<\/a> published after the Sansec advisory went live, FishPig said that the intruders used their access to inject malicious PHP code into a Helper\/License.php file that&#8217;s included in most FishPig extensions. After launching, Rekoobe removes all malware files from disk and runs solely in memory. For further stealth, it hides as a system process that tries to mimic one of the following:<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>\/usr\/sbin\/cron -f<br \/>\/sbin\/udevd -d<br \/>crond<br \/>auditd<br \/>\/usr\/sbin\/rsyslogd<br \/>\/usr\/sbin\/atd<br \/>\/usr\/sbin\/acpid<br \/>dbus-daemon &#8211;system<br \/>\/sbin\/init<br \/>\/usr\/sbin\/chronyd<br \/>\/usr\/libexec\/postfix\/master<br \/>\/usr\/lib\/packagekit\/packagekitd<\/p>\n<p>The backdoor then waits for commands from a server located at 46.183.217.2. Sansec said it hadn&#8217;t detected follow-up abuse from the server yet. The security firm suspects that the threat actors may plan to sell access to the affected stores in bulk on hacking forums.<\/p>\n<p>Tideswell declined to say how many active installations of its paid software there are. <a href=\"https:\/\/packagist.org\/packages\/fishpig\/\">This post<\/a> indicates that the software has received more than 200,000 downloads, but the number of paid customers is smaller.<\/p>\n<p>In the email, Tideswell added:<\/p>\n<blockquote>\n<p>The exploit was placed right before the code was encrypted. By placing the malicious code here, it would be instantly obfuscated by our systems and hidden from anyone who looked. If any client then enquired about the obfuscated file, we would reassure them that the file was supposed to be obfuscated and was safe. The file was then undetectable by malware scanners.<\/p>\n<p>This is a custom system that we developed. The attackers couldn&#8217;t have researched this online to find out about it. Once inside, they must have reviewed the code and made a decision about where to deploy their attack. They chose well.<\/p>\n<p>This has all been cleaned up now and multiple new defences have been installed to stop this from happening again. We are currently in the process of rebuilding our entire website and code deployment systems anyway and the new systems we already have in place (which aren&#8217;t live yet) already have defenses against attacks like this.<\/p>\n<\/blockquote>\n<p>Both Sansec and FishPig said customers should assume that all modules or extensions are infected. FishPig recommends users immediately upgrade all FishPig modules or reinstall them from source to ensure none of the infected code remains. Specific steps include:<\/p>\n<blockquote>\n<h3>Reinstall FishPig Extensions (Keep Versions)<\/h3>\n<div class=\"code\">rm -rf vendor\/fishpig &amp;&amp; composer clear-cache &amp;&amp; composer install &#8211;no-cache<\/div>\n<h3>Upgrade FishPig Extensions<\/h3>\n<div class=\"code\">rm -rf vendor\/fishpig &amp;&amp; composer clear-cache &amp;&amp; composer update fishpig\/* &#8211;no-cache<\/div>\n<h3>Remove Trojan File<\/h3>\n<p>Run the command below and then restart your server.<\/p>\n<div class=\"code\">rm -rf \/tmp\/.varnish7684<\/div>\n<\/blockquote>\n<p>Sansec advised customers to temporarily disable any paid FishPig extensions, run a server-side malware scanner to detect any installed malware or unauthorized activity, and then restart the server to terminate any unauthorized background processes.<\/p>\n<p><em>The headline of this post has been changed.<\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/33836\/Breach-Of-Software-Maker-Used-To-Backdoor-As-Many-As-200-000-Servers.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":48447,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[4207],"class_list":["post-48446","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-14T14:52:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/data-breach-800x435.jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers\",\"datePublished\":\"2022-09-14T14:52:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/\"},\"wordCount\":808,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg\",\"keywords\":[\"headline,hacker,backdoor\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/\",\"name\":\"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg\",\"datePublished\":\"2022-09-14T14:52:41+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg\",\"width\":800,\"height\":435},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/","og_locale":"en_US","og_type":"article","og_title":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-09-14T14:52:41+00:00","og_image":[{"url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/data-breach-800x435.jpeg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers","datePublished":"2022-09-14T14:52:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/"},"wordCount":808,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg","keywords":["headline,hacker,backdoor"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/","url":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/","name":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg","datePublished":"2022-09-14T14:52:41+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/09\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers.jpg","width":800,"height":435},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/breach-of-software-maker-used-to-backdoor-as-many-as-200000-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerbackdoor\/"},{"@type":"ListItem","position":3,"name":"Breach Of Software Maker Used To Backdoor As Many As 200,000 Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=48446"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/48447"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=48446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=48446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=48446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}