WordPress sites are being hacked to display fake Cloudflare pages to protect against DDoS attacks, with the real purpose of distributing malware. The fake notifications install the NetSupport RAT and RaccoonStealer, a trojan known for stealing passwords.

It is not uncommon for users to see “ DDoS Protection ” pages when browsing the web. These DDoS protection pages are usually related to browser checks performed by WAF/CDN services, which verify whether the website visitor is, in fact, a human or is part of a (DDoS) attack
Internet users treat these “welcome screens” as an unavoidable short-term annoyance that keeps their favorite online resources safe from malicious enterprises. Unfortunately, however, this familiarity with these notifications can backfire.
See also: Hackers target hotels and infect systems with malware
installation via fake Cloudflare messages for DDoS protection
As detailed in a report by Sucuri, threat actors are hacking into under-protected WordPress sites to add an obfuscated JavaScript payload that displays a fake screen DDoS protection.
This screen asks the visitor to click a button to bypass the DDoS protection screen. However, clicking the button downloads a file 'security_install.iso' which is supposedly a tool required to bypass DDoS verification.
Victims are then asked to open security_install.iso, which appears as an application named DDOS GUARD, and enter the code that appears.

When the user opens security_install.iso, they will see a file called security_install.exe, which is actually a Windows that runs a PowerShell command from the debug.txt file.

See also: 35 Android malware apps found in Google Play Store
Ultimately, this triggers the execution of a chain of scripts (which display the fake DdoS code required to view the site), as well as the installation of the NetSupport RAT, a remote access trojan widely used in malicious campaigns.
Additionally, the scripts will download the Raccoon Stealer to steal passwords. Raccoon Stealer began to be used again in June, when its creators released its second major version and made it available to cybercriminals on a subscription model.
Raccoon 2.0 targets passwords, cookies, auto-fill data, and credit cards stored in browsers. It also targets various cryptocurrency wallets and can extract files and take screenshots of the victim's desktop.
See also: Malware devs are already bypassing Android 13 security

Ways of protection
Remote Access Trojans (RATs) are one of the worst types of infections that can affect a computer, as they give attackers complete control over the device. Site owners and visitors should take every precaution to protect themselves.
According to Sucuri, the following can help reduce the risk of infection.
Site owners :
- Keep all software on your website up to date
- Use strong passwords
- Use 2FA in the admin panel
- Use a firewall
- Use file integrity monitoring systems
visitors :
- Make sure your computer is running a strong antivirus program
- Implement 2FA on all important connections (e.g. bank, social media)
- Practice good browsing habits. Don't open strange files!
- Keep your browser and all software on your computer up to date
- Use a script blocker in your browser (advanced)
Source: www.bleepingcomputer.com
