Hackers often exploit legitimate online services and websites to stage their attacks and perform their tricks. Quite often, the online clipboard service Pastebin is used for this purpose, in order to steal useful personal information and data from unsuspecting users.
Lately, however, the popular service has not only been used for this purpose, but also to host files full of viruses and malware.
Senior security researcher Denis Sinegubko of security firm Sucuri has made public his discovery of online attacks in which hackers used the service to upload and run malicious scripts.
The attackers had targeted a WordPress site, with older versions of the RevSlider plugin, which had a known vulnerability that allowed the site to be compromised and a backdoor to be set up.
“It’s more or less a typical backdoor. It downloads the malicious script from a remote server and stores it in a file on the website, making it available for execution at any time.” In this case, the remote server is Pastebin, which allows users to download the infected script and run it.
"Technically, hackers use Pastebin for what it is designed to do, which is to share code snippets. The only illegality is that the code is malicious and is used in illegal activities (hacking) directly from the service's website," Sinegubko explained.
In fact, this service is so useful to hackersthat hackers from Indonesia have developed an encoder that works specifically with Pastebin to camouflage malicious code.
Pastebin attempts to identify and remove illegal material (such as stolen info), but it is impossible to search through all the code on a website for malicious scripts.

