Hacked WordPress sites use visitors' browsers to hack other sites
ID: abf02e06-8aba-502b-9211-ac4f24fbe2a9
STIX ID: report--abf02e06-8aba-502b-9211-ac4f24fbe2a9
Feed Name: Bleeping Computer
Threat actors are compromising thousands of WordPress sites to inject JavaScript that either drains crypto wallets (AngelDrainer) or coerces site visitors' browsers into executing distributed brute‑force attacks against other WordPress sites via a tasking service (dynamic-linx.com). The campaign abuses injected JS and WordPress XML-RPC to exfiltrate credentials and credentials candidates, has been observed at scale (~1,700+ compromised sites), and uses identifiable domains and script paths as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
