Alpha Cyber

How Attackers Hijack Web Traffic Through System-Level CeidPageLock Rootkits

CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit.

Alpha Cyber Research2 min readupdated 1 Apr 2026
CeidPageLock Rootkit

CeidPageLock Chinese Rootkit: Attack Techniques and Advanced Mapping for Enterprise Defense

CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit. It hijacks browsers, monitors user activity, and redirects victims to fake web pages for data theft and revenue, making it a serious backdoor threat for business environments.

CEIDPageLock Rootkit Graph

How CeidPageLock Works: Tactics of Chinese Threat Actors

1. Exploit Kit Distribution

  • Attackers deploy CeidPageLock via the RIG exploit kit, exploiting browser and system vulnerabilities to download and execute the rootkit on targeted endpoints.

2. Dropper and Driver Mechanism

  • The dropper extracts a signed kernel-mode driver (houzi.sys) to the Windows temp directory.

This driver is stealthy, hard to detect, and launches at system startup, operating with deep privileges.

  • The driver connects to hard-coded C2 domains, receives encrypted instructions, and sends identifiers (MAC address, user ID) from infected machines to the attacker’s infrastructure.

3. Browser Hijacking & Redirection

  • CeidPageLock hooks into the system’s network driver stack (AFD), monitoring all outgoing HTTP requests.
  • When users visit specific popular websites, the rootkit swaps the received content for a malicious fake homepage (e.g., 111.l2345.cn, pretending to be 2345.com).
  • Instead of classic redirects, it covertly changes page content so the browser URL remains unchanged, users are unaware they are viewing a fake page.

4. Data Harvesting & Monetization

  • The malware records sites visited and time spent, forwarding this information for advertising, profiling, or criminal resale.
  • Attackers make money from ad revenue on fake sites and by selling stolen browsing data.

5. Anti-Detection and Evasion

  • CeidPageLock blocks browsers from accessing key antivirus files, making remediation difficult.
  • VMProtect is used for code obfuscation, making detection and analysis hard for most endpoint security products.
  • It creates registry modifications within security products (like 360Safe) to disable protection functions.

6. Geographic Targeting

  • The rootkit mostly targets machines in China, but global businesses have been affected, organizations with international users are at risk.

Infrastructure Mapping & Automated IOC Blocking

Advanced infrastructure mapping tools are essential to:

  • Spot infected endpoints: Map out locations, detect kernel-level threats, and block command-and-control (C2) attempts in real time.
  • Visualize redirection paths: See how user traffic is manipulated internally and externally.
  • Monitor registry changes: Flag unauthorized modifications to security product settings.
  • Control lateral movement: Stop propagation across the enterprise by visualizing dropper distribution routes and network connections.

CeidPageLock IOC Table (Integrate with Mapping Tools)

TypeValueDescription
Domainwww[.]tj999[.]topRedirection / C2 Domain
IP Address42.51.223.86Active C2 Server
IP Address118.193.211.11Payload Delivery Node
MD5 HashC7A5241567B504F2DF18D085A4DDE559Packed Dropper
MD5 HashF7CAF6B189466895D0508EEB8FC25948Kernel Driver (houzi.sys)
MD5 Hash1A179E3A93BF3B59738CBE7BB25F72ABUnpacked Dropper

Don’t Wait. Harden Your Business Security Today.

Our cybersecurity mapping and IOC automation tools help you spot, quarantine, and neutralize threats like CeidPageLock before they cripple your operations.

Contact us

today to get a tailored risk assessment, live demo, and actionable roadmap to keep your users and digital infrastructure safe.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]