Over 39,000 WordPress websites have been infiltrated by a huge malware operation known as Sign1 in the last six months. Sign1 uses malicious JavaScript injections to divert users to scam websites.
Sucuri reported last week that the most recent iteration of the malware is thought to have compromised at least 2,500 websites in the last two months alone.
To give attackers the chance to upload their malicious code, the assaults involve inserting rogue JavaScript into genuine HTML widgets and plugins that permit the insertion of arbitrary JavaScript and other code.
After being XOR-encoded, the JavaScript code is decoded and utilized to run a JavaScript file hosted on a remote server. This allows redirection to be made to a traffic distribution system (TDS) run by VexTrio, but only in certain scenarios.
Furthermore, the malware circumvents blocklists by fetching dynamic URLs that read more Massive Sign1 Campaign Infects 39000+ WordPress Sites with Scam Redirects.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
