Compromised WordPress Site Uses Traffic Direction System to Target Windows Users With GULoader
ID: 78424f8c-e6f5-54a0-99e2-54b7f53c4fd8
STIX ID: report--78424f8c-e6f5-54a0-99e2-54b7f53c4fd8
Feed Name: Cyber Press
Threat Score
A compromised small-business WordPress site silently injected JavaScript to fingerprint visitors and used a TDS plus blockchain-hosted payloads (EtherHiding) to selectively show a fake reCAPTCHA (ClickFix) to Windows desktop users; the lure pasted a rundll32 UNC command from the clipboard to attempt GULoader execution. The chain was validated by ANY.RUN sandboxing and endpoint telemetry, and the attempted infection was intercepted by endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
