Categories: hackingviruswordpress

New Attack on WordPress Sites Redirects Traffic to Malicious URLs

New Attack on WordPress Sites Redirects Traffic to Malicious URLs

Security consultants from Sucuri have disclosed these days associate in progress attack on WordPress sites that alters their ASCII text file and surreptitiously redirects users to malicious websites.
According to an associate investigation by Sucuri’s John Fidel Castro Ruz, attackers square measure mistreatment vulnerabilities in older WordPress versions or WordPress plugins to achieve access to a website, and that they square measure then redaction the most theme’s header.php file by adding twelve lines of obfuscated code.
Sucuri says that, in some cases, the attackers managed to get the site’s admin credentials by different means that, and simply logged in via the site’s regular login page, accessed the WordPress inbuilt theme editor section, and additional the malicious ASCII text file by hand.

Some Joomla sites additionally affected

The security firm additionally points out that, besides WordPress, they’ve additionally seen this same malicious code additional to Joomla sites within the administrator/includes/help.php file. yet, the quantity of infected Joomla websites is way smaller.
Sucuri says the campaign remains in progress which, in an associate earlier version, the crooks were adding an equivalent obfuscated code within the theme’s footer.php file.
After unpacking the malicious ASCII text file, the protection firm says the practicality they found is easy nonetheless effective. Crooks square measure telling every website to pick out incoming users with a fifteen % probability and direct them to a preset address. The malicious ASCII text file additionally sets a cookie within the user’s browser, that prevents from redirecting the user once more within the coming year.

The malicious sites square measure gateways to a lot of dangerous threats

Sucuri says these square measure mere gateways to different insecure domains. Once the user reaches these gateways, they are redirected to different and different a lot of dangerous sites. In one amongst the cases discovered by Sucuri, users using net humans were redirected to websites that pushed malware-infected downloads created to seem like authentic Adobe Flash or Java updates.
Jerome Segura of Malwarebytes additionally according that his company saw equivalent entranceway domains, direct users, to technical school support scams.

At least 6,400 sites square measure infected

Because of varied PHP setups and a few unhealthy secret writing within the malicious PHP code, on some infected websites, the code generated a slip. Softpedia googled the error at the time of writing the article and discovered precisely half dozen,400 infected websites, albeit the important variety of infected WordPress installations is clearly higher.

Yashwant Shakyawal

Recent Posts

9 Best Free WordPress SEO Plugins In 2025

Check Best Free WordPress SEO Plugins in 2025. Search engines are a Bigger source of…

2 weeks ago

9 Best Premium WordPress Event Calendar Plugins 2025

Do you host various pursuits for your WordPress website? Or might be you might be…

3 weeks ago

How to Scale Your WooCommerce Store for Peak Traffic Events

How to Scale Your WooCommerce Store: WooCommerce stores are advantageous. But let’s not forget about…

1 month ago

Data-Driven Workforce Management: Employee Monitoring in the Digital Marketing Era

Data-Driven Workforce Management: How do successful digital marketing teams stay productive and deliver results on…

2 months ago

Tips for Setting up Mobile Printing and Scanning on your Smartphone or Tablet

This guide explores the convenience of mobile printing and scanning, showing how to manage documents…

2 months ago

What is Digital Document Management?

Digital document management is vital for organizations aiming to streamline operations, enhance collaboration, bolster security,…

2 months ago