Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
ID: c5ea22af-74d1-5a60-ba6b-ffeb580cf771
STIX ID: report--c5ea22af-74d1-5a60-ba6b-ffeb580cf771
Feed Name: The Hacker News
Threat Score
A large-scale campaign named Sign1 has compromised over 39,000 WordPress sites by injecting XOR-encoded JavaScript into custom HTML widgets and plugins (frequently via the Simple Custom CSS and JS plugin or through brute-force/exploit of plugins/themes). The injected code decodes and fetches remote scripts that use time-based randomized domains and referrer checks to evade blocklists and then redirect visitors to scam sites through a VexTrio-operated traffic distribution system.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
