
Approximately 6,700 WordPress sites using a vulnerable version of the Popup Builder plugin have been infected by the Balada Injector malware in a campaign that started in December.
See also: Microsoft: Windows 10 WinRE update with BitLocker fixes
Initially documented by Dr. Web researchers who observed coordinated waves of attacks exploiting known bugs in WordPress themes and plugins, it was later discovered that Balada Injector was a massive operation that had been operating since 2017 and had compromised more than 17,000 WordPress websites.
The attacks incorporate a backdoor that redirects visitors to infected websites to fake support pages, sweepstakes pages , and push notification scams.
The most recent Balada Injector campaign began on December 13, 2023, two days after WPScan reported CVE-2023-6000, a cross-site scripting (XSS) vulnerability in versions 4.2.3 and earlier of Popup Builder.
Popup Builder is used on 200,000 websites to create custom popups for marketing, information, and operational purposes.
Website security firm Sucuri reports that Balada Injector was quick to incorporate an exploitable bug that hijacks the “sgpbWillOpen” event in Popup Builder and executes malicious JavaScript in the website’s database when the popup is launched.
See also: Framework Computer: Suffered a data breach
Malicious Javascript code that runs when a window opens
Sucuri observed that the attackers also used a secondary infection method, modifying the wp-blog-header.php to encourage the same malicious JavaScript backdoor.
The attacker then checks for cookies associated with administrators and allows them to load various sets of scripts to embed the main backdoor, which is presented as a plugin named 'wp-felody.php'.

Researchers report that the infection never stops at the first step and the integration of the main backdoor always follows the initial breach.
The function of the backdoor ‘felody’ includes arbitrary execution of PHP code, uploading and executing files, communicating with the attackers and receiving additional payloads.
Currently, the number of WordPress websites affected by the Balada Injector Malware campaign has reached 6,700 websites.
See also: Bitwarden: Now supports passkeys to access password vaults
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Sucuri's analysis of the domains used for these attacks reveals a pattern in their registration, suggesting an attempt to conceal the true origin of the attacks that also involves the use of Cloudflare.
According to security researcher Randy McEoin, the redirects in this campaign point to push notification scams.

Defending against Balada Injector attacks requires WordPress website administrators to update themes and plugins to their latest versions and remove products that are no longer supported or necessary for the website.
Maintaining a small number of active plugins on a WordPress site reduces the attack surface and minimizes the risk of compromise from automated scripts.
Source: bleepingcomputer
