Sucuri has observed a rise in the number of unsafe websites as part of a malicious campaign based on thousands of compromised WordPress websites![]()
According to experts at Sucuri, attackers have hijacked thousands of WordPress CMS websites to distribute malware. The technique is an old one, with legitimate websites hosting malicious exploits that are used by crooks to distribute malware. They have also been used to redirect visitors to a server hosting the Nuclear Exploit Kit, which is very popular among cybercriminals.
What's new in this latest research by Sucuri is that the campaign began 15 days ago, and researchers noticed a spike in the number of unsafe websites over the past 48 hours, from 1,000 a day on Tuesday to about 6,000 on Thursday. On the same day, the company discovered that thousands of these sites, 95% of which were running WordPress. Experts, still investigating how the hackers compromised the sites, suspect that the attackers exploited vulnerabilities in WordPress plugins.
Bad news for website administrators, 17% of hacked websites have been blacklisted by a Google.
When victims visit a compromised website, the malicious code hosted on it attempts a number of different exploits, depending on the operating system and applications available on the device.
"This malicious campaign is interesting, its ultimate goal is to use as many sites as possible to redirect all visitors to the Nuclear Exploit Kit landing page . These landing pages will try a wide range of exploits to infect the computers of unsuspecting visitors."
The security firm has named the campaign “Visitor Tracker” as one of the names of the functions used in the malicious code is “visitorTracker_isMob()”.
Sucuri researchers also discovered that the hackers behind the campaign have managed to compromise security provider Coverity and are exploiting it to redirect victims to compromised websites.
Sucuri urges administrators to check their pages for evidence of the breach.

