Over 5,000 WordPress Sites Infected with Keylogger
ID: 5d3ab66c-2426-5a55-8781-f3777a408e24
STIX ID: report--5d3ab66c-2426-5a55-8781-f3777a408e24
Feed Name: Binary Defense Blog
Security researchers observed that more than 5,000 WordPress sites were infected by a malware tracked as “Cloudeflare.solutions,” which initially performed cryptomining and has been updated to include a keylogger. The malware injects code into themes' functions.php, uses counterfeit Cloudflare-like domains to deliver payloads, aims to harvest login credentials and target e-commerce platforms for banking fraud, and defenders are advised to remove the malicious add_js_scripts function and related add_action clauses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
