logo

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

ID: c5ea22af-74d1-5a60-ba6b-ffeb580cf771

STIX ID: report--c5ea22af-74d1-5a60-ba6b-ffeb580cf771

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A large-scale campaign named Sign1 has compromised over 39,000 WordPress sites by injecting XOR-encoded JavaScript into custom HTML widgets and plugins (frequently via the Simple Custom CSS and JS plugin or through brute-force/exploit of plugins/themes). The injected code decodes and fetches remote scripts that use time-based randomized domains and referrer checks to evade blocklists and then redirect visitors to scam sites through a VexTrio-operated traffic distribution system.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.