Evasive Sign1 malware campaign infects 39,000 WordPress sites
ID: 7b73d002-7a5d-55f6-9e1a-492c4c63c0ce
STIX ID: report--7b73d002-7a5d-55f6-9e1a-492c4c63c0ce
Feed Name: Bleeping Computer
Threat Score
**Sign1 malware campaign:** Sucuri observed a WordPress-focused malware campaign that has infected over 39,000 sites in six months by injecting obfuscated JavaScript (via custom HTML widgets or the Simple Custom CSS and JS plugin) that uses time-based dynamic domains, XOR encoding, referrer/cookie checks, and hosting/domain-hopping to redirect visitors to scam captchas and push-notification ad fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
