HomeSecurityWordPress sites hacked: Fake plugins promote info-stealer malware

WordPress sites hacked: Fake plugins promote info-stealer malware

Thousands of WordPress sites have been hacked to install malicious plugins that display fake software updates and errorsto promote info-stealer malware.

WordPress plugins info-stealer malware

This type of malware is very dangerous, as the stolen credentials are used to compromise networks and steal data. Since 2023, a malicious campaign called ClearFakehas been displaying fake banners with alleged browser updates on compromised websites. The goal is to trick users into trying to update their browser and eventually getting infected with malware.

In 2024, a new campaign called ClickFix, displaying software error messages and urging users to fix the problem. However, these “fixes” are PowerShell scripts that, when executed, will download and install info-stealer malware.

See also: LiteSpeed ​​Cache WordPress: New vulnerability allows XSS attacks

Researchers have observed ClickFix campaigns that hack websites to display fake errors for Google Chrome, Google Meet, Facebook , and more.

Malicious WordPress plugins

Last week, GoDaddy reported that cybercriminals have compromised over 6,000 WordPress websites to install malicious plugins that display fake alerts related to the ClearFake/ClickFix campaigns.

“The GoDaddy Security team is tracking a new variant of the ClickFix (also known as ClearFake) campaign with fake browser updates, distributed via fake WordPress plugins,” explains GoDaddy security researcher Denis Sinegubko.

“These seemingly legitimate plugins are designed to appear harmless to website administrators, but they contain embedded malicious scripts that deliver fake browser update messages to end users“.

Malicious plugins use names similar to legitimate plugins, such as Wordfense Security and LiteSpeed ​​Cache.

Η λίστα των κακόβουλων plugins που εμφανίζονται σε αυτήν την καμπάνια (μεταξύ Ιουνίου και Σεπτεμβρίου 2024) είναι:

LiteSpeed Cache ClassicCustom CSS Injector
MonsterInsights ClassicCustom Footer Generator
Wordfence Security ClassicCustom Login Styler
Search Rank EnhancerDynamic Sidebar Manager
SEO Booster ProEasy Themes Manager
Google SEO EnhancerForm Builder Pro
Rank Booster ProQuick Cache Cleaner
Admin Bar CustomizerResponsive Menu Builder
Advanced User ManagerSEO Optimizer Pro
Advanced Widget ManageSimple Post Enhancer
Content BlockerSocial Media Integrator

Website security company Sucuri reported a fake plugin called “Universal Popup Plugin” that is also part of this campaign.

See also: Security vulnerabilities in Houzez WordPress Theme and Plugin

Once installed, the malicious plugin will do several things to inject a malicious JavaScript script into the website's HTML. When loaded, this script will attempt to load an additional malicious file , which then loads the ClearFake or ClickFix script to display the fake updates/errors.

It appears that initially the attackers use stolen administrator credentials to log in to WordPress sites and install the plugin in an automated manner.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Once they log in, the attackers upload and install the malicious plugin.

WordPress site administrators should be very careful and check for user reports of update notifications. They should check the list of installed plugins and remove any that are not installed by the administrators. If unknown plugins are found, it is also recommended to immediately reset the passwords for the admin users.

WordPress sites hacked: Fake plugins promote info-stealer malware

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

See also: WordPress will require 2FA from plugin developers

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers  ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS