Hackers deploy crypto drainers on thousands of WordPress sites
Fake NFT and discount pop-ups are already appearing on around 2,000 compromised WordPress websites, tricking users into connecting their wallets to cryptocurrency drainers that automatically steal money.
Last month, the website security company Sucuri revealed that hackers had gained access to almost 1,000 WordPress sites in order to spread cryptocurrency drainers through YouTube videos and malvertising.
It is thought that when their initial campaign proved unsuccessful, the threat actors started using news scripts on the hacked websites to enable users' web browsers to be used as instruments for brute-forcing admin passwords on other websites.
Approximately 1,700 brute-forcing websites were targeted in these attacks; well-known examples include the website of Ecuador's Associati...

