Security researchers from the company Sucuri have discovered an interesting online attack targeting WordPress website owners.
The attack began with a WordPress email scam informing beneficiaries that they have been “selected” to take part in the company’s customer loyalty program. Since they are among the “only winners,” they receive the All in One SEO Pack Pro plugin for free.
The funny thing is, the download link provided by the email does not lead to the developer's website or the WordPress Plugin Directory. Instead, it redirects victims to a compromised website created to host what appears to be All in One SEO Pack Pro.
The plugin delivered to users is a modified version of the legitimate application. The cybercriminals have placed a backdoor that gives them full access to the infected server. The backdoor has been added to a file called aioseop_class.php.
Once implemented, the malware replaces the existing index.php file with one designed to display malicious content to website visitors. Users can be directed to spam websites or those hosting exploit kits.
One might think that WordPress website owners wouldn't fall victim to such a trick, but Sucuri says it has identified a number of websites that had the malicious plugin installed.

