Over the past four years, a malicious malware campaign known as Balada Injector has affected more than a million WordPress websites.

GoDaddy's Sucuri has detected a large-scale attack exploiting themes and plugins for WordPress websites. The attacks are known to occur in waves once every few weeks.
It is alarming that the reported websites are fraudulent and malicious. Fake technical support redirects users to fake lottery winnings, while deceptive CAPTCHA pages encourage them to activate notifications with the misleading appeal 'Please Allow to verify, that you are not a robot,' when in reality these websites exist solely to send spam ads after user permission.
A recent report from Doctor Web revealed a sneaky Linux malware family that exploits vulnerabilities in over two dozen plugins and themes to infiltrate WordPress websites. This new research builds on those discoveries by providing more insight into the malicious activity.
Over the past few years, the Balada Injector has exploited over 100 domains and a variety of methods to exploit existing security vulnerabilities (such as HTML injection and Site URL). Attackers primarily targeted obtaining database credentials from the wp-config.php file.
Additionally, these malicious attacks are specifically designed to view or download website files, such as backups, database dumps, and log/error documents. In addition, attackers look for leftover tools like adminer and phpmyadmin, which website administrators may have forgotten about after completing maintenance tasks.

The malware ultimately allows the creation of fake WordPress administrator users, harvesting data stored on the underlying hosts, and leaving backdoors for permanent access.
Balada Injector further performs broad searches of top-level directories related to the compromised website's file system to locate "writable directories" belonging to other websites.
If these attack pathways prove unavailable, the admin password is brute-forced using a set of 74 predefined credentials. Therefore, WordPress users are advised to keep their website software up to date, remove unused plugins and themes, and use strong WordPress admin passwords.
Just a few weeks after Palo Alto Networks' Unit 42 discovered a malicious JavaScript, findings revealed that more than 51,000 websites have been affected since 2022.
The activity, which also uses String.fromCharCode as an obfuscation technique, leads victims to booby-trapped pages that trick them into enabling push notifications by masquerading as a fake CAPTCHA to display misleading content.
Information source: thehackernews.com
