Documented Security Incidents

Incident 1

HypeX Digital and hypesrilanka.com suffered a significant security breach on March 9, 2026.

Nature of the Attack

  • The incident involved an automated botnet.

  • Attackers exploited a vulnerability within the 3D Viewer for Elementor plugin.

Technical Impact

  • Backdoor Suite: The attack deployed a backdoor suite using the inactive MetaSync folder.

  • Data Exfiltration: Attackers exfiltrated database credentials and site salts.

  • Persistence: The botnet established persistence using shadow admin accounts and malicious cron jobs.

  • Client-Side Infection: Malicious JavaScript was injected to facilitate client-side data theft.

  • System Disguise: The breach included the creation of “Trojan Mimic” files designed to look like internal system signatures.

Discovery and Mitigation

  • Detection: The breach was identified through bounce messages from Zoho Mail, which flagged the exfiltration attempts.

  • Response: Recovery required a server-level purge and the implementation of immutable file permissions.

  • Hardening: Enforcement of strict Content Security Policy (CSP) headers was part of the final remediation.

  • Implemented the Malware Sentry plugin.