Mpack Attacks Originate From Porn Sites

LOS ANGELES — A wave of cyber attacks said to be originating from several hundred pornography websites has exposed surfers to the notorious Mpack hacker toolkit. The attacks were launched from a network of more than 10,000 compromised domains, according to Computer World.

Mpack, developed by Russian hackers, is a collection of exploits that compromises the security of infected PCs. Close to 200 porn domain names have been hacked to redirect to servers hosting Mpack. The attacks were said to have begun June 17.

“The pornographic sites, which tend to specialize on incestuous content, have an obfuscated I-Frame code appended at the end of the HTML code,” Ryan Flores said on the Trend Micro blog. “This I-Frame redirects to another domain that will serve a script file to download a copy of TROJ_AGENT.QMN. Right now, we are not sure whether the porn sites are compromised to host the I-Frames, are created to do so, or are being paid to host the I-Frames.”

Symantec security analyst Amado Hidalgo told Computer World that he believes the “Mpack gang appears to be using an I-Frame manager tool to automate the task on a large scale,” which is how the hackers were able to infect so many sites in a short time. This manager tool is successful because it injects the malicious I-Frame code to the sites’ HTML that redirects surfers to the Mpack server.

“It takes as input a list of website administrator accounts, possibly obtained in the black market,” Hidalgo said. These accounts are logged into the manager tool, which enables previously purged sites to become re-infected.

“A simple cleanup of the page is not sufficient,” Hidalgo said. “The site administrator’s credentials need to be changed.”

Mpack was created by a hacker who goes by the name $ash. The toolkit sells for around $1,000.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

NATS Launches Integrated Content Management System

Too Much Media (TMM) has rolled out an integrated, no-charge Content Management System (CMS) to its NATS platform.

AEBN Reveals Avery Lust as Top Trans Star for Q3 of 2025

AEBN has published its top trans stars list for the third quarter of 2025, with Avery Lust landing atop the leaderboard.

FSC: California's Device-Based AV Law Does Not Apply to Adult

The Free Speech Coalition (FSC) put out an advisory today explaining that California's new device-based age verification law does not apply to adult websites.

Reena Sky Launches New Paysite

Reena Sky has launched her new official paysite, ILoveReenaSky.com.

NextGen Payment Joins ASACP as Corporate Sponsor

NextGen Payment has signed on as the latest corporate sponsor for the Association of Sites Advocating Child Protection (ASACP).

Lauren Phillips, Derek Kage Cap AEBN's Top Stars for 3rd Quarter of 2025

AEBN has revealed its most popular performers in straight and gay theaters for the third quarter of 2025.

XBIZ 2026 Conference to Debut All-New Company Lounges, Community Track

The event website for XBIZ 2026 is now live, unveiling details for North America’s largest adult industry conference, including two all-new show features: Company Lounges and a Community Track.

Mymember.site Integrates VR Functionality

Mymember.site has added virtual reality playback capability to its website management platform.

Texas Patti to Launch Fetish Platform 'EmpireDom'

Performer and content creator Texas Patti is launching a new platform for doms and fetish creators, EmpireDom.com.

Ohio AG Threatens Action Against 'Major' Adult Sites Over AV Law

Ohio Attorney General Dave Yost announced today that his office is sending "notice of violation" letters to 19 adult websites for failure to comply with the state's recently enacted age verification law.

Show More