Hackers deploy crypto drainers on thousands of WordPress sites
ID: 551ca454-8283-555a-88e3-1934c8ef71c4
STIX ID: report--551ca454-8283-555a-88e3-1934c8ef71c4
Feed Name: Bleeping Computer
Threat Score
Security firms report that threat actors have compromised approximately 1,000–2,000 WordPress sites and are loading malicious scripts from dynamic-linx.com which randomly display fake NFT and discount pop-ups to trick visitors into connecting crypto wallets; once connected, the crypto drainers steal funds and NFTs. The scripts check for a specific cookie ("haw"), support MetaMask, WalletConnect and other wallets, and have been observed across over 2,000 sites in the past week.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
