According to researchers, WordPress have been under continuous attack since last month by hackers using administrator accounts. Vulnerabilities in WordPress plugins are used by hackers, who “inject” malicious JavaScript into the frontends of sites . Through this, site visitors can be led to sites with malware. Many times the payloads try to avoid detection by WAF and IDS software.
Researchers were able to trace the source of the attacks by identifying several IP addresses associated with web hosting providers. When the attacks became known, the IP addresses stopped their activity. Only one continued.
“The IP address in question is 104.130.139.134, a Rackspace serverthat hosts several compromised sites. Researchers contacted Rackspace to inform them of the suspicious activity.
Hackers exploited known vulnerabilities in the following plugins:
- Bold Page Builder
- Blog Designer
- Live Chat with Facebook Messenger
- Yuzo Related Posts
- Visual CSS Style Editor
- WP Live Chat Support
- Form Lightbox
- Hybrid Composer
- All former NicDark plugins (nd-booking, nd-travel, nd-learning, et. al.)
Initial research identified the injection of scripts that led site visitors to malicious content.
However, the campaign has evolved and added an additional script that aims to install a backdoor on the targeted site.
Researchers advise users to constantly update their WordPress site plugins and receive the latest patches to combat such attacks.
According to researchers, attacks are moving from the server to the client. At the same time, they are becoming more insidious and harder to detect.
Publishers, platforms, and brands need to think about what they need to do to prevent malicious activity. They should consider strengthening cyber-security programs. This will help remove any malicious hackers from the network and reduce the risk to end users.
