How Attackers Hijack Web Traffic Through System-Level CeidPageLock Rootkits
CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit.

CeidPageLock Chinese Rootkit: Attack Techniques and Advanced Mapping for Enterprise Defense
CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit. It hijacks browsers, monitors user activity, and redirects victims to fake web pages for data theft and revenue, making it a serious backdoor threat for business environments.

How CeidPageLock Works: Tactics of Chinese Threat Actors
1. Exploit Kit Distribution
- Attackers deploy CeidPageLock via the RIG exploit kit, exploiting browser and system vulnerabilities to download and execute the rootkit on targeted endpoints.
2. Dropper and Driver Mechanism
- The dropper extracts a signed kernel-mode driver (houzi.sys) to the Windows temp directory.
This driver is stealthy, hard to detect, and launches at system startup, operating with deep privileges.
- The driver connects to hard-coded C2 domains, receives encrypted instructions, and sends identifiers (MAC address, user ID) from infected machines to the attacker’s infrastructure.
3. Browser Hijacking & Redirection
- CeidPageLock hooks into the system’s network driver stack (AFD), monitoring all outgoing HTTP requests.
- When users visit specific popular websites, the rootkit swaps the received content for a malicious fake homepage (e.g., 111.l2345.cn, pretending to be 2345.com).
- Instead of classic redirects, it covertly changes page content so the browser URL remains unchanged, users are unaware they are viewing a fake page.
4. Data Harvesting & Monetization
- The malware records sites visited and time spent, forwarding this information for advertising, profiling, or criminal resale.
- Attackers make money from ad revenue on fake sites and by selling stolen browsing data.
5. Anti-Detection and Evasion
- CeidPageLock blocks browsers from accessing key antivirus files, making remediation difficult.
- VMProtect is used for code obfuscation, making detection and analysis hard for most endpoint security products.
- It creates registry modifications within security products (like 360Safe) to disable protection functions.
6. Geographic Targeting
- The rootkit mostly targets machines in China, but global businesses have been affected, organizations with international users are at risk.
Infrastructure Mapping & Automated IOC Blocking
Advanced infrastructure mapping tools are essential to:
- Spot infected endpoints: Map out locations, detect kernel-level threats, and block command-and-control (C2) attempts in real time.
- Visualize redirection paths: See how user traffic is manipulated internally and externally.
- Monitor registry changes: Flag unauthorized modifications to security product settings.
- Control lateral movement: Stop propagation across the enterprise by visualizing dropper distribution routes and network connections.
CeidPageLock IOC Table (Integrate with Mapping Tools)
| Type | Value | Description |
|---|---|---|
| Domain | www[.]tj999[.]top | Redirection / C2 Domain |
| IP Address | 42.51.223.86 | Active C2 Server |
| IP Address | 118.193.211.11 | Payload Delivery Node |
| MD5 Hash | C7A5241567B504F2DF18D085A4DDE559 | Packed Dropper |
| MD5 Hash | F7CAF6B189466895D0508EEB8FC25948 | Kernel Driver (houzi.sys) |
| MD5 Hash | 1A179E3A93BF3B59738CBE7BB25F72AB | Unpacked Dropper |
Don’t Wait. Harden Your Business Security Today.
Our cybersecurity mapping and IOC automation tools help you spot, quarantine, and neutralize threats like CeidPageLock before they cripple your operations.
Contact us
today to get a tailored risk assessment, live demo, and actionable roadmap to keep your users and digital infrastructure safe.



