Skip to content

Parrot TDS

Parrot TDS is a malicious traffic direction system used to route visitors from compromised websites into downstream attack chains.

Profile source: Mallory opens in a new tab

Parrot TDS

Family profile

Parrot TDS is a malicious traffic direction system used to route visitors from compromised websites into downstream attack chains. It emerged at scale in late 2021 and early 2022, leveraging large numbers of hacked content management system sites, particularly WordPress and Joomla, across sectors including personal, academic, government, and adult-content websites. Its role is to fingerprint visitors and selectively redirect only qualifying targets, making it an enabling component for broader malware delivery operations rather than a conventional endpoint payload family.

Parrot TDS operates by injecting malicious JavaScript into compromised websites and, in some cases, by deploying server-side PHP components on the victim web server. Observed filtering logic evaluates attributes such as IP address, user agent, referrer, and cookies, and commonly limits redirection to a single visit per user to reduce exposure and hinder analysis. Responses are delivered as client-side JavaScript that either suppresses further requests for non-selected users or forwards selected victims into follow-on campaigns. A proxied variant has also been observed using malicious server-side scripts that relay traffic to command-and-control infrastructure while additionally enabling arbitrary code execution on the compromised server, effectively functioning as a backdoor on the web host.

The most prominent downstream campaign associated with Parrot TDS has been FakeUpdate, also known as SocGholish. In those chains, compromised pages are modified to display fraudulent browser update prompts that lead to staged malware delivery. Observed follow-on activity includes victim fingerprinting, execution of PowerShell-based intermediate payloads, and deployment of NetSupport Client as a remote access tool with stealth and persistence mechanisms. Parrot TDS has also appeared in supply-chain-style website compromises involving tampered JavaScript libraries, where injected logic fingerprints browsers and selectively serves malicious content.

Parrot TDS primarily targets website visitors through compromised web infrastructure while also compromising the servers that host the injected content. Its core value to threat operators lies in selective targeting, anti-analysis controls, and scalable redirection into malware or phishing campaigns.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Spoofing

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Aug 26, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • DigitalOcean, LLC1

Infrastructure traits

  • Hosting 1

MITRE ATT&CK

Parrot TDS in ATT&CK

7 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.