This Sunday started with a bang. Google blacklisted over 11,000 domains with the latest malware from the domain SoakSoak.ru:

The analysis carried out by Sucuri shows that the number of affected sites is in the order of 100,000 and concerns specific Word Press. However, the exact carrier has not been confirmed, but a preliminary analysis shows a correlation with the Revslider which was discovered a few months ago.

The attack appears to be affecting most hosts across the WordPress hosting.
The anatomy of the “Soak Soak” malware
Through the attack, the wp-includes/template-loader.php is modified to include this content:
This results in the wp-includes/js/swobject.js on every page of the website, which includes the malware.
This malware when decoded loads a JavaScript malware from the SoakSoak.ru and specifically this file: hxxp://soak soak.ru/xteas/code

