Mpack Attacks Originate From Porn Sites

LOS ANGELES — A wave of cyber attacks said to be originating from several hundred pornography websites has exposed surfers to the notorious Mpack hacker toolkit. The attacks were launched from a network of more than 10,000 compromised domains, according to Computer World.

Mpack, developed by Russian hackers, is a collection of exploits that compromises the security of infected PCs. Close to 200 porn domain names have been hacked to redirect to servers hosting Mpack. The attacks were said to have begun June 17.

“The pornographic sites, which tend to specialize on incestuous content, have an obfuscated I-Frame code appended at the end of the HTML code,” Ryan Flores said on the Trend Micro blog. “This I-Frame redirects to another domain that will serve a script file to download a copy of TROJ_AGENT.QMN. Right now, we are not sure whether the porn sites are compromised to host the I-Frames, are created to do so, or are being paid to host the I-Frames.”

Symantec security analyst Amado Hidalgo told Computer World that he believes the “Mpack gang appears to be using an I-Frame manager tool to automate the task on a large scale,” which is how the hackers were able to infect so many sites in a short time. This manager tool is successful because it injects the malicious I-Frame code to the sites’ HTML that redirects surfers to the Mpack server.

“It takes as input a list of website administrator accounts, possibly obtained in the black market,” Hidalgo said. These accounts are logged into the manager tool, which enables previously purged sites to become re-infected.

“A simple cleanup of the page is not sufficient,” Hidalgo said. “The site administrator’s credentials need to be changed.”

Mpack was created by a hacker who goes by the name $ash. The toolkit sells for around $1,000.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Pornhub Awards Fiesta: A Night of Music, Dancing and Camaraderie

The eighth annual Pornhub Awards transformed Los Candiles Night Club in Glassell Park into a celebration of glamour, glitter, fashion and fame Wednesday night, as performers, creators and industry insiders toasted the year’s winners and danced late into the night while Diplo and Midnight Mary kept the party pulsing from behind the decks.

Ukrainian Parliament Rejects Porn Decriminalization Bill

The Verkhovna Rada, Ukraine’s parliament, on Thursday voted against passage of a bill that would have decriminalized the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

FSC Launches Pride Fundraising Drive

The Free Speech Coalition (FSC) has launched its Pride Fundraising Drive to support its efforts on behalf of the LGBTQ+ community.

Cultpix Debuts AI-Generated Vintage Adult Films at Cannes

At this year’s Cannes Film Festival, B-movie streaming service Cultpix debuted a collection of AI-generated short films drawn from erotic magazine photo spreads published 50 years ago.

Ofcom Fines Youngtek Solutions $800K for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed fines totaling 600,000 pounds (more than $800,000) against adult site operator Youngtek Solutions for failing to implement age checks and respond to information requests as required for compliance with the Online Safety Act.

Pornhub Launches Lesbian Site 'Pornhub Sapphic'

Pornhub has launched Pornhub Sapphic, a site dedicated to female and non-binary content and creators.

Brazil Invites Public Input on AV Guidelines

Brazil’s National Data Protection Authority (ANPD) on Friday launched a public consultation on developing guidelines for age verification mechanisms under the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

Paysite Confidential: Inside the Creator Economy's Shift Toward Ownership

For years, the adult industry’s creator economy has been defined by platforms — powerful engines of discovery, monetization and scale that reshaped how performers connect with their audiences.

Senator Urges DOJ to Crack Down on 'Obscenity,' Attacks OnlyFans

U.S. Senator Jim Banks of Indiana this week urged Acting Attorney General Todd Blanche to reestablish the Department of Justice’s defunct Obscenity Prosecution Task Force in a letter that targets OnlyFans while repeatedly conflating “obscenity” with legal adult content.

UN Experts Urge US, Canada to Prosecute Aylo, Others for 'Exploitation'

GENEVA – The United Nations Office of the High Commissioner for Human Rights (OHCHR) has issued a press release in which two U.N. special rapporteurs, cited as experts, accuse Aylo and other companies of complicity in sexual exploitation.

Show More