Skip to content
June 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Border Security Force website has been used to spread malware
  • Malware

Border Security Force website has been used to spread malware

Do Son April 9, 2018 3 minutes read
Add as a preferred
source on Google

An official website of the Border Security Force (BSF) in India was hacked and used to spread malware. The website is currently https://bsf. [gov] .in is offline.

After the MalwareHunter team tweet on April 6, the malware issue was known to the public. The malware they found on the BSF website called SocketPlayer had never appeared before. “Just found that the website of “Border Security Force of India” (https://bsf.[gov].in/) has been used to spread malware in past weeks. Checked two of the samples (highlighted on screenshot): one is SocketPlayer main, another is SocketPlayer loader (both crypted). Interesting.”

Just found that the website of "Border Security Force of India" (https://bsf.[gov].in/) has been used to spread malware in past weeks.
Checked two of the samples (highlighted on screenshot): one is SocketPlayer main, another is SocketPlayer loader (both crypted).
Interesting.
🤔 pic.twitter.com/IQQhVo0cFS

— MalwareHunterTeam (@malwrhunterteam) April 6, 2018

 

They also stated that “All source links that I could find (possible that there are ones that wasn’t scanned, so I couldn’t find) on screenshot. Currently, the whole site is down (503 error), so couldn’t verify if the files are removed or not…”

In addition, Yash Kadakia, chief technology officer of Security Brigade, a Mumbai-based information security company, analyzed the malware. Kadakia said that “From an initial look, it appears that once downloaded, these infected files work by accessing a person’s contact lists through a mail client like Outlook to send out emails pretending to be from the United Services Club in Mumbai. The email then triggers another malware which can remotely access one’s system from attacker-controlled servers in Germany and the USA”

Malware researcher Bart revealed on the 7th that he had attacked the BSF website as a hacker. The Webshell hosted on the “India Border Security Force” is a typical WSO webshell, modified by “DrSpy”. Auth_pass is decoded as “cyberrose”, which is clearly a Pakistani hacker organization.

The Times of India reported on the incident on April 8. A BSF spokesperson claimed that the website has already realized these problems. “The website has been under security audit for the last 30-40 days. Concerned officials are comprehensively studying various elements of the website and why they were behaving in a certain manner.”

A few hours after the Times of India reported, the MalwareHunter team was openly unbelievable about the BSF staff’s claims. If BSF officials say it is true, it means that BSF’s “review” is more than two months before “SocketPlayer” began using the site to spread their malicious software. “Currently, every single SocketPlayer sample we know of, are either were seen on BSF’s website, or they are samples that were downloaded by the samples seen there.“

Related coverage

  • The Hidden Threat: Android Apps with VajraSpy RAT Exposed
  • Chalubo Malware Wreaks Havoc: Half a Million Routers Permanently Disabled
  • Threat Group TA4557 Exploits Recruiters for Malware Delivery
  • RansomHub: A New Ransomware-as-a-Service Threatens Multiple Operating Systems
  • North Korean Threat Group “Jumpy Pisces” Linked to Play Ransomware Attack

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Border Security Force

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.