Compromised WordPress Campaign - Spyware Edition
ID: bad3f72b-0ddc-54ec-86ed-8f6a0be6a014
STIX ID: report--bad3f72b-0ddc-54ec-86ed-8f6a0be6a014
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ investigated a large-scale campaign (since August 2015) where compromised WordPress, Joomla, and Drupal pages had injected JavaScript that loaded an iframe pointing to a Latvia-hosted VPS (91.226.33.54). The iframe fingerprinted visitors (timestamp, timezone, Flash presence) and triggered redirects to download fake installers (e.g., Adobe Flash Player.exe -> Flash Setup.exe, Win32.InstallCore; Setup.exe variant Win32.DownloadAssistant) and browser plugins, enabling installation of spyware/PUAs and follow-on unwanted software. The report provides domains, sample filenames and MD5s, infection flow, and global site distribution, and notes Zscaler is monitoring and protecting customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
