A custom made drive-by download attack targets some Chinese websites and their visitors while experimenting with exploits. The campaign we stumbled upon starts with sites that were compromised to load external content via scripts and iframe overlays. The threat actor reused the same code already published here and altered the DownloadUr to point to their malicious binary. Users (unless their browser settings have been changed) will be presented with a prompt asking them to install this piece of malware. The final payload dropped in this campaign is a DDoS bot.”]

