Image depicting WordPress security features, highlighting tools and measures for enhancing website protection and safety.

More than 6,000 WordPress websites have been hijacked by an ongoing malware campaign that installed malicious plugins that spread malware that steals personal information. The effort, called ClearFake, started in 2023 and uses phony browser error messages to mislead people into installing malware.

The spyware, which targets both Windows and macOS users, has the ability to steal confidential information, according to BleepingComputer. Infostealers such as AMOS Stealer on macOS and StealC and Rhadamanthys on Windows are among the malware used in these assaults.

Malicious WordPress plugins that propagate malware frequently seem just like genuine ones, such as Wordfence Security, making them difficult to identify. These plugins load extra scripts stored on Binance Smart Chain by inserting malicious JavaScript into the HTML of hacked websites. Security researchers at GoDaddy have monitored these fraudulent plugins and discovered that hackers install them using administrator credentials that have been stolen.

WordPress administrators are advised to routinely check their websites for strange plugins and to reset admin credentials right away if any questionable behavior is found in order to reduce the risk.

Recently, ClickFix, a similar continuing scam, has grown to use phony Google Meet sites to trick people into running malicious PowerShell scripts. Phishing emails pose as Google Meet invitations, and when victims click on the link, they are taken to fake websites that mimic real Google Meet conferences. Fake technical faults are displayed on these pages, leading visitors to copy and execute a command that eventually infects their machine with malware that steals personal information.

Attackers are using social engineering techniques in addition to technological flaws in both situations. WordPress websites are especially vulnerable because of plugin flaws that give hackers administrator access. Site managers should make sure plugins are constantly up to date and routinely monitor for unusual activity in order to lessen these risks.

6,000 WordPress Websites With Infostealer Malware on Them Details

Languages:
Established:

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent Comments

No comments to show.

New Providers
Tunnel Bear

2GB free per month
Includes strong encryption, user-friendly interface, and access to 8,000+ servers worldwide.

Hotspot Shield

10 devices supported
Includes a 45-day money-back guarantee and features advanced malware protection.

Vypr VPN

30-day money-back guarantee
Includes Chameleon™ protocol for bypassing restrictions, split tunneling, and 10 simultaneous connections.

Surf Shark

Unlimited devices
Includes antivirus, ad blocker, and a private search engine for safer browsing.

Express VPN

3 months free
Includes unlimited bandwidth, high-speed Lightway protocol, and 24/7 live chat support.

6,000 WordPress Websites With Infostealer Malware on Them
0.0/10
Copyright Notice © https://top-privacy-vpn.com/, 2024. All rights reserved. The logo and design of this website are the exclusive property of https://top-privacy-vpn.com/ and are protected by international copyright laws. All other logos and trademarks belong to their respective VPN providers. The information and comparisons provided are for informational purposes and belong to https://top-privacy-vpn.com/. Unauthorized use, reproduction, or distribution of this website’s design, logo, and content is strictly prohibited without prior written permission. For permissions or inquiries, please contact : support@top-privacy-vpn.com