Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Aug 26, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Parrot TDS is a malicious traffic direction system used to route visitors from compromised websites into downstream attack chains.
Profile source: Mallory opens in a new tabParrot TDS
Parrot TDS is a malicious traffic direction system used to route visitors from compromised websites into downstream attack chains. It emerged at scale in late 2021 and early 2022, leveraging large numbers of hacked content management system sites, particularly WordPress and Joomla, across sectors including personal, academic, government, and adult-content websites. Its role is to fingerprint visitors and selectively redirect only qualifying targets, making it an enabling component for broader malware delivery operations rather than a conventional endpoint payload family.
Parrot TDS operates by injecting malicious JavaScript into compromised websites and, in some cases, by deploying server-side PHP components on the victim web server. Observed filtering logic evaluates attributes such as IP address, user agent, referrer, and cookies, and commonly limits redirection to a single visit per user to reduce exposure and hinder analysis. Responses are delivered as client-side JavaScript that either suppresses further requests for non-selected users or forwards selected victims into follow-on campaigns. A proxied variant has also been observed using malicious server-side scripts that relay traffic to command-and-control infrastructure while additionally enabling arbitrary code execution on the compromised server, effectively functioning as a backdoor on the web host.
The most prominent downstream campaign associated with Parrot TDS has been FakeUpdate, also known as SocGholish. In those chains, compromised pages are modified to display fraudulent browser update prompts that lead to staged malware delivery. Observed follow-on activity includes victim fingerprinting, execution of PowerShell-based intermediate payloads, and deployment of NetSupport Client as a remote access tool with stealth and persistence mechanisms. Parrot TDS has also appeared in supply-chain-style website compromises involving tampered JavaScript libraries, where injected logic fingerprints browsers and selectively serves malicious content.
Parrot TDS primarily targets website visitors through compromised web infrastructure while also compromising the servers that host the injected content. Its core value to threat operators lies in selective targeting, anti-analysis controls, and scalable redirection into malware or phishing campaigns.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.