• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Border Security Force website has been used to spread malware
  • Malware

Border Security Force website has been used to spread malware

Ddos April 9, 2018 3 minutes read

An official website of the Border Security Force (BSF) in India was hacked and used to spread malware. The website is currently https://bsf. [gov] .in is offline.

After the MalwareHunter team tweet on April 6, the malware issue was known to the public. The malware they found on the BSF website called SocketPlayer had never appeared before. “Just found that the website of “Border Security Force of India” (https://bsf.[gov].in/) has been used to spread malware in past weeks. Checked two of the samples (highlighted on screenshot): one is SocketPlayer main, another is SocketPlayer loader (both crypted). Interesting.”

Just found that the website of "Border Security Force of India" (https://bsf.[gov].in/) has been used to spread malware in past weeks.
Checked two of the samples (highlighted on screenshot): one is SocketPlayer main, another is SocketPlayer loader (both crypted).
Interesting.
🤔 pic.twitter.com/IQQhVo0cFS

— MalwareHunterTeam (@malwrhunterteam) April 6, 2018

 

They also stated that “All source links that I could find (possible that there are ones that wasn’t scanned, so I couldn’t find) on screenshot. Currently, the whole site is down (503 error), so couldn’t verify if the files are removed or not…”

In addition, Yash Kadakia, chief technology officer of Security Brigade, a Mumbai-based information security company, analyzed the malware. Kadakia said that “From an initial look, it appears that once downloaded, these infected files work by accessing a person’s contact lists through a mail client like Outlook to send out emails pretending to be from the United Services Club in Mumbai. The email then triggers another malware which can remotely access one’s system from attacker-controlled servers in Germany and the USA”

Malware researcher Bart revealed on the 7th that he had attacked the BSF website as a hacker. The Webshell hosted on the “India Border Security Force” is a typical WSO webshell, modified by “DrSpy”. Auth_pass is decoded as “cyberrose”, which is clearly a Pakistani hacker organization.

The Times of India reported on the incident on April 8. A BSF spokesperson claimed that the website has already realized these problems. “The website has been under security audit for the last 30-40 days. Concerned officials are comprehensively studying various elements of the website and why they were behaving in a certain manner.”

A few hours after the Times of India reported, the MalwareHunter team was openly unbelievable about the BSF staff’s claims. If BSF officials say it is true, it means that BSF’s “review” is more than two months before “SocketPlayer” began using the site to spread their malicious software. “Currently, every single SocketPlayer sample we know of, are either were seen on BSF’s website, or they are samples that were downloaded by the samples seen there.“

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Updated ShadowPad Malware Facilitates Ransomware Deployment in Global Attacks
  2. PolarEdge Botnet: 2,000+ IoT Devices Infected
  3. XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected
  4. Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
  5. “Contagious Interview” Goes macOS: North Korean Hackers Deploy Stealthy “DriverFixer” Stealer
Tags: Border Security Force

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.