WordPress, the Internet's favorite content management system, is a common target for criminals who want to redirect innocent users to malware download sites.
A new type of malware steals users' login credentials, leaving everything else unchanged.
“It’s an interesting attack — we haven’t seen it before,” said Michael Sutton, VP Security Research at cloud security vendor Zscaler, Inc., which recently released a report on the malware.
"WordPress tends to be a very common target for attacks," he said. "It's widely used, but it tends to be quite insecure and not well maintained. Typically, they inject some code to redirect the browser to download malware and thus join the machine to a botnet."
The open source WordPress software currently accounts for two-thirds of the content management system market, according to W3Techs, and powers a quarter of all websites.
In this new attack, WordPress pages receive an unwanted JavaScript, but instead of redirecting users to a different site, it steals their credentials as they try to log in.
"This is a harder one to detect," he said.
Sites that try to download malware are trying to install something on the user's machine.
"But if my certificates are compromised, I wouldn't have any knowledge that anything was wrong," Sutton said.
So far, Zscaler has identified 18 exposed websites, each of which sends certificates to the same destination domain, “conyouse.com.”
If the domain name changes, Sutton said, Zscaler can still protect its customers by looking for special code, variables and behaviors.
“Don’t use the same credentials on two different sites,” Sutton says. “Now that there are some really good password management tools available, it’s very easy to have a very-hard-to-crack password on every single site you use.”
[signoff icon=”icon-target”]According to his statement, the reason cybercriminals steal login credentials is not so much to break into users' personal accounts on the specific sites from which the theft occurs, but to try to reuse the same credentials elsewhere, such as email or social networking sites.[/signoff]
"And because people usually reuse their certificates, they have success," he said.

According to the research so far, they are able to see that the infected sites were running either WordPress 4.1.5 or WordPress 4.2.2. The latter is the most recent version of the software.

