Spyware and PUAs (potentially unwanted applications) are transmitted from compromised WordPress websites to users, via fake messages that prompt to Flash updates and fake browser plugins.
Researchers at Zscaler have discovered a spyware based on compromised WordPress websites, which redirect users to infected URLs.
According to their findings, the campaign started in the first week of August, and in total more than 2,000 sites have been compromised and more than 20,000 users have been infected.
A closer look at the infected websites revealed that they were running the latest version of the WordPress CMS, version 4.3.1. Being the latest and most secure version, Zscaler staff estimates that most of the websites were infected on older versions, before the core update.
In the most recent campaign that was detected, the targeted websites deliver malicious JavaScript code to users. When the code is executed in the user's browser, it loads an iframe, which in turn loads more JavaScript code that allows the collection and interception of information from the victims' computers, which is sent to a C & C server.
When the data are collected from the local system and sent to the C & C server, the user is redirected to a website, which most often asks them to install a fake update of the Adobe Flash Player. In the case that the user proceeds with installation, then in reality they have installed a variant of the Win32.InstallCore PUA.
After installing the malicious software, the user is redirected to the real Adobe website, where it is informed that the installation of Flash Player failed, and is asked to try again, this time from the original and authentic source.
Zscaler researchers also observed that, in some cases, instead of the fake update of the Adobe Flash Player version, users were prompted to install various browser add-ons.
Even though all these software (spyware, scareware, adware and PUAs) are low-level eavesdropping tools, they are nevertheless dangerous, mainly because they can later be used as entry points for more harmful malware. This is due to the fact that almost all modern malware these days have the capability to download other viruses and trojans onto already infected computers.

