How is it technically realized that "gangs hijack traffic and steal 3 billion pieces of user data fortunately the police stop the leak"?

Why can operator servers get cookie? Is it because if these companies use HTTP?HTTPS, cookie should be encrypted, right? Then the operators and these companies should be responsible!

the police revealed that in order to hijack the operator"s traffic, Xing and his criminal gang put the malicious program written independently on the server within the operator in order to hijack the operator"s traffic. when the user"s traffic passes through the operator"s server, the program works automatically, cleaning and collecting user cookie, access records and other key data, and then exporting all the data through malicious programs. It is stored on a number of servers inside and outside Ruizhihua.

the so-called cookie, is equivalent to the login credentials of a user"s account. Through cookie, you can enter a user"s account without entering the account and password again, and you can obtain the user"s registration information, search record, room record and other data from the user"s account.

the criminal gang took advantage of this feature of cookie and logged in a large number of user accounts through hijacked cookie data, thus manipulating user accounts to add powder, brush, and promote malicious pop-up windows to make illegal profits. " Shan Zhongying, a policeman handling the case, said that in order to achieve a better cash effect, Rui Zhihuasheng developed software for different scenarios such as adding powder and brushing quantity, with extremely professional modus operandi and high technical level.

original text: gangs hijack traffic and steal 3 billion pieces of user data fortunately the police stopped leaking

Apr.15,2021
Menu