Security researcher Denis Sinegubko says a massive advertising scam campaign is affecting users visiting WordPress sites by installing backdoors and continuously re-infecting the sites.

Virus destroyer (@unmaskparasites) says that the attackers are injecting code into all JavaScript on targeted sites. According to the researcher, for the first time, users will encounter a cookie that generates fraudulent revenue for the Vxers.
“Last weekend we noticed a sharp increase in WordPress where hackers had put encrypted code at the end of all .js files,” Sinegubko said.
This malware uploads multiple backdoors to various locations on the webserver and frequently updates the code. This is why many webmasters face constant re-infections even after cleaning their .js files.
The researcher says that the malware will infect all accessible .js files on all domains located on the same hosting account, which is known as cross-site infection.
It is not enough to clean just one site or all of them because an abandoned site will always be the source of re-infection. In other words, you must either isolate all sites or clean, update and protect them all at the same time.
The malware uses encrypted code that mutates between sites but decrypts to the same structure! It installs an advertising cookie that places invisible iframes on sites over a 24-hour period.
Sinegubko notes that the malware that has infected WordPress uses domain shadowing , which is a favorite trick of Vxers to add malicious subdomains to second-level domains after gaining access to DNS records.
Read also on SecNews:
https://www.secnews.gr/100892/facebook-phishing-malware-scam-message/«You have a new Facebook Message» >> BEWARE of the new Scam!!
