Watering‑Hole Campaign Plants ScanBox Keylogger on Target Sites
APT group TA423 is leveraging compromised legitimate websites as watering‑hole vectors. When a user visits an infected page, the site silently redirects the browser to a malicious JavaScript payload that injects the ScanBox keylogger. The script records keystrokes in real time and forwards the captured data to the attackers’