A hacking group tracked as MUT-1244has stolen over 390,000 WordPress accounts in a large-scale campaign targeting other malicious actors using a trojanized WordPress credential checker.
See also: Woffice: Vulnerabilities in WordPress theme – Update now!

Hacker groups refer to entities that seek to cause harm or damage to the systems, applications, and data of users or organizations. The groups include hackers, cyberattacks, malware, physical security breaches, and more. Understanding the different malicious actors and taking appropriate security measures is crucial to protecting systems and data from attacks and losses.
Researchers at Datadog Security Labs, who discovered the attacks, say that private SSH keys and AWS access keys were also stolen from the compromised systems of hundreds of other victims, believed to include red teamers, penetration testers, security researchers, as well as malicious actors.
Victims were infected using the same second-stage payload that was pushed through dozens of trojanized GitHub repositories delivering malicious PoCs targeting known security flaws, along with a phishing that pushes targets to install a fake kernel upgrade camouflaged as a CPU microcode update.
While phishing emails tricked victims into executing commands that installed malware, fake repositories tricked security professionals and threat actors looking for exploit code for specific flaws. Malicious actors have used fake PoCs in the past to target researchers, hoping to steal valuable research or gain access to cybersecurity companies’ networks.
See also: Hunk Companion: Critical vulnerability in WordPress plugin

The payloads were dropped via GitHub repositories using multiple methods, including backdoored configuration files, malicious PDF files, Python droppers, and malicious npm packages included in project dependencies.
As Datadog Security Labs found, this campaign coincides with one highlighted in a Checkmarkx reportabout a year-long supply chain attack in which the trojanized GitHub project “hpc20235/yawp” used malicious code in the npm package “0xengine/xmlrpc” to steal data and mine the Monero.
The malware deployed in these attacks includes cryptocurrency mining and a backdoor that helped the MUT-1244 group collect and exploit private SSH keys, AWS credentials, environment variables, and key directory contents such as “~/.aws“.
The second-stage payload, hosted on a separate platform, allowed attackers to exfiltrate data on file-sharing services like Dropbox and file.io, with researchers finding encoded credentials for these platforms within the payload, giving attackers easy access to the stolen information.
The attackers successfully exploited trust in the cybersecurity community to compromise dozens of machines belonging to white hat and black hat hackersafter the targets unknowingly executed the threat actor's malware, leading to data theft that included SSH keys, AWS access tokens, and command histories.
See also: WPForms bug allows refunds on millions of WordPress sites
Datadog Security Labs estimates that hundreds of systems remain at risk, while others continue to be infected as part of this ongoing campaign.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
