logo

Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks

ID: 764c3a9c-dfa1-533a-9e83-73e1cc7e6719

STIX ID: report--764c3a9c-dfa1-533a-9e83-73e1cc7e6719

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors are actively using malicious JavaScript injected into compromised WordPress sites (observed on 700+ sites) to perform distributed brute-force attacks from the browsers of unsuspecting visitors, attempting common and leaked passwords via the wp.uploadFile XML-RPC API and writing successful credentials to uploads. The report ties this activity to prior waves that distributed crypto drainers and FakeUpdates/SocGholish schemes, and notes exploitation of a high-severity WordPress plugin flaw (CVE-2021-4436) used to deploy web shells for persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.