logo

Compromised WordPress Campaign - Spyware Edition

ID: bad3f72b-0ddc-54ec-86ed-8f6a0be6a014

STIX ID: report--bad3f72b-0ddc-54ec-86ed-8f6a0be6a014

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ investigated a large-scale campaign (since August 2015) where compromised WordPress, Joomla, and Drupal pages had injected JavaScript that loaded an iframe pointing to a Latvia-hosted VPS (91.226.33.54). The iframe fingerprinted visitors (timestamp, timezone, Flash presence) and triggered redirects to download fake installers (e.g., Adobe Flash Player.exe -> Flash Setup.exe, Win32.InstallCore; Setup.exe variant Win32.DownloadAssistant) and browser plugins, enabling installation of spyware/PUAs and follow-on unwanted software. The report provides domains, sample filenames and MD5s, infection flow, and global site distribution, and notes Zscaler is monitoring and protecting customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.