"While traditionally these redirects led to scams, the malware has evolved recently to execute remote content ... written in ...