logo

Hacked WordPress sites use visitors' browsers to hack other sites

ID: abf02e06-8aba-502b-9211-ac4f24fbe2a9

STIX ID: report--abf02e06-8aba-502b-9211-ac4f24fbe2a9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-06

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Threat actors are compromising thousands of WordPress sites to inject JavaScript that either drains crypto wallets (AngelDrainer) or coerces site visitors' browsers into executing distributed brute‑force attacks against other WordPress sites via a tasking service (dynamic-linx.com). The campaign abuses injected JS and WordPress XML-RPC to exfiltrate credentials and credentials candidates, has been observed at scale (~1,700+ compromised sites), and uses identifiable domains and script paths as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.