
Security experts at Heimdal Security have identified a new ransomware campaign that relies on the Neutrino Exploit Kit to spread the Teslacrypt ransomware to victims via websites running older versions of WordPress.
Researchers do not rule out the possibility that attacks can be carried out through other Content Management Systems (CMSs) or through outdated CMS plugins, but in most of the observed cases, older versions of WordPress.
According to Heimdal's report, attackers are exploiting known vulnerabilities in older WordPress websites (or plugins) by compromising the systems, then injecting malicious scripts into the source code. These scripts redirect users to websites hosting the Neutrino exploit kit.
Neutrino then, utilizing advanced capabilities and features, while exploiting security vulnerabilities in software such as Adobe Flash Player, Adobe Reader, or Internet Explorer, infects victims with a variant of the Teslacrypt ransomware.
[signoff icon=”icon-target”]According to the researchers, thedancingbutterfly.co was used by the attackers to store malicious scripts that redirected users to the nkzppqzzzumhoap.ml website, where the exploit kit was hosted. The latter domain is hosted in the Netherlands, on the servers of a Web hosting company that has been used in the past to host similar malicious campaigns.[/signoff]
After infiltrating victims' computers, the Teslacrypt ransomware takes action by locking a number of files, while also leaving a .txt and a .html file on the user's desktop, explaining the process required to successfully recover the files.
In some cases, in addition to encrypting files, the ransomware downloads and installs an infostealer based on Pony malware, which originates from the light-tech.pl domain.
