{"id":6648,"date":"2025-09-04T10:03:36","date_gmt":"2025-09-04T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/massive-iptv-hosted-across-more-than-1000-domains-and-over-10000-ip-addresses\/"},"modified":"2025-09-04T10:03:36","modified_gmt":"2025-09-04T10:03:36","slug":"massive-iptv-hosted-across-more-than-1000-domains-and-over-10000-ip-addresses","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/massive-iptv-hosted-across-more-than-1000-domains-and-over-10000-ip-addresses\/","title":{"rendered":"Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses"},"content":{"rendered":"<p>    Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sprawling network of illicit Internet Protocol Television (IPTV) services has been discovered, operating across more than 1,100 domains and in excess of 10,000 IP addresses.<\/p>\n<p>This sprawling infrastructure, which has remained active for several years, delivers unauthorized streams of premium content\u2014including major sports leagues, subscription services, and on-demand platforms\u2014without licensing agreements.<\/p>\n<p>Silent Push analysts noted that this network\u2019s use of both high-volume IP address pools and rapidly rotating domains represents a significant escalation in piracy tactics, making traditional takedown processes nearly futile.<\/p>\n<p>At its core, the <a href=\"https:\/\/cybersecuritynews.com\/network-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">network<\/a> relies on customized IPTV panels built around modified open-source software such as Stalker Portal and Xtream UI.<\/p>\n<p>These panels facilitate automated user authentication and stream distribution, allowing operators to provision hundreds of thousands of simultaneous sessions.<\/p>\n<p>Rather than depending on a single front-end domain, the operators employ a large pool of proxy domains\u2014each resolving to multiple shared IP addresses\u2014to obfuscate the true origin of the streams.<\/p>\n<p>Silent Push researchers identified two companies, XuiOne and Tiyansoft, and an individual, Nabi Neamati of Herat, Afghanistan, as principal beneficiaries of this infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhp_r3kb0OrHhO55UkFKhbVIbpqQPJc3S_NaTC3_gER7aUYKyJ7ZnKHNSP3wZl9FQQlBycEAgXh2RT9KuPwksDRhia_xaQ69T985GO32n3qlbqgCjuexz-zOc_WB-vRxY1f1qww5T0V6hA-6u5_oIhUGc_6Vh3FQOkt5_jNdYGkZy_Ycq5EjQpehfVRi7k\/s16000\/XUIone%2520website%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">XUIone website (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>The attack vectors begin with server-side exploitation and credential harvesting. Malicious actors compromise under-protected web hosts or exploit outdated control panels to install custom modules that inject backdoors into legitimate streaming control software.<\/p>\n<p>In many cases, operators gain initial access by exploiting default credentials on cPanel, Plesk, and Stalker Portal installations.<\/p>\n<p>Once access is secured, a deployment script\u2014often <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> via Base64 encoding\u2014pushes modified PHP files and cron jobs to automate the registration of new domains and the rotation of stream endpoints.<\/p>\n<p>Silent Push analysts <a href=\"https:\/\/www.silentpush.com\/blog\/iptv-piracy\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> one such script that uses the following code snippet to register new virtual hosts:<\/p>\n<pre class=\"wp-block-code\"><code>$domain = trim(shell_exec('wp option get siteurl'));\n$ipList = ['158.220.114.199','46.202.197.208'];\nforeach ($ipList as $ip) {\n    shell_exec(\"echo '$domain IN A $ip' &gt;&gt; \/etc\/bind\/db.piracy\");\n}\nshell_exec('rndc reload');<\/code><\/pre>\n<p>Despite repeated takedown requests, the network\u2019s agility in rotating both domains and IP addresses allows it to remain operational.<\/p>\n<p>New domains appear almost daily, with each resolving to clusters of dynamic IP addresses provisioned via bullet-proof hosting providers.<\/p>\n<p>This resilient structure poses a formidable challenge to rights holders and law enforcement agencies attempting to disrupt the service.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-through-control-panel-exploits\"><strong>Infection Mechanism Through Control Panel Exploits<\/strong><\/h2>\n<p>A particularly insidious aspect of this IPTV piracy network is its infection mechanism, which centers on compromised control panels.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhWVPucdSEv6vWvPllB7YJB-dz7F1FVv_gEjHXEgkKgcKnTGo3dHZ3k3X-PIal-odkg656yQVzGLkFTpiFWKUoTfycENK8sOgoCVXAuuCOJh8Rx-L17f9WcSPd6PvSeiX5JNVqQztf4wvmULrCL3cshTu2QNyqhvLcfHhMFUSOfHTtOHtF9EJKpz3jqrUY\/s16000\/Xtream%2520UI%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Xtream UI (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>Operators survey the internet for misconfigured or outdated installations of Stalker Portal and Xtream UI, using automated scanners to detect vulnerable endpoints on ports 80, 8080, and 2095.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzY0lKtbUHV0vjFw22n0wh1tUnAdze3DHpoZsrccrEWlxsmuZPuTmmTMbC_JsV2UxfNss4YS-AoQCQKuMLSL9h1lNAouwldYdJbbMp-1sO2E0G94tJSBosCujF6m7DjA5ZaHOPL9adD-Hsbgbes8hkQ6qCjj_ET8SBag-XW6IZnAUZhUfej61i_X-OybM\/s16000\/Stalker%2520Portal%2520and%2520Xtream%2520portal%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Stalker Portal and Xtream portal (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>Upon identifying a target, they deploy a <a href=\"https:\/\/cybersecuritynews.com\/konni-apt-hackers-using-multi-stage-malware-to-attack-organizations\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-stage payload<\/a> that begins with a low-profile reconnaissance module.<\/p>\n<p>This module enumerates existing user accounts, collects hashed credentials, and exfiltrates configuration files containing API keys.<\/p>\n<p>A second stage installs a persistent backdoor by modifying the <code>config.php<\/code> file within the panel\u2019s directory:-<\/p>\n<pre class=\"wp-block-code\"><code>if (!defined('IPTV_INIT')) {\n    define('IPTV_INIT', true);\n    require_once __DIR__ . '\/backdoor.php';\n}<\/code><\/pre>\n<p>The backdoor script, <code>backdoor.php<\/code>, establishes a reverse shell to a command-and-control server whenever an administrator logs in, effectively granting the attackers full control over the panel.<\/p>\n<p>This persistent foothold enables continuous updates to the hosting infrastructure, seamless domain registration, and dynamic IP assignment\u2014ensuring that new entry points replace any that have been taken down.<\/p>\n<p>As a result, the network can sustain large-scale <a href=\"https:\/\/cybersecuritynews.com\/video-game-piracy-websites-seized\/\" target=\"_blank\" rel=\"noreferrer noopener\">piracy operations<\/a> with minimal interruption.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/massive-iptv-hosted-across-more-than-1000-domains\/\">Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/massive-iptv-hosted-across-more-than-1000-domains\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses A sprawling network of illicit Internet Protocol Television (IPTV) services has been discovered, operating across more than 1,100 domains and in excess of 10,000 IP addresses. This sprawling infrastructure, which has remained active for several years, delivers unauthorized streams of premium content\u2014including [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6648","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6648"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6648"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6648\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}