Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks
ID: 764c3a9c-dfa1-533a-9e83-73e1cc7e6719
STIX ID: report--764c3a9c-dfa1-533a-9e83-73e1cc7e6719
Feed Name: The Hacker News
Threat actors are actively using malicious JavaScript injected into compromised WordPress sites (observed on 700+ sites) to perform distributed brute-force attacks from the browsers of unsuspecting visitors, attempting common and leaked passwords via the wp.uploadFile XML-RPC API and writing successful credentials to uploads. The report ties this activity to prior waves that distributed crypto drainers and FakeUpdates/SocGholish schemes, and notes exploitation of a high-severity WordPress plugin flaw (CVE-2021-4436) used to deploy web shells for persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
