Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
Over 39,000 WordPress websites have been infiltrated by a huge malware operation known as Sign1 in the last six months. Sign1 uses malicious JavaScript injections to divert users to scam websites.
Sucuri reported last week that the most recent iteration of the malware is thought to have compromised at least 2,500 websites in the last two months alone.
To give attackers the chance to upload their malicious code, the assaults involve inserting rogue JavaScript into genuine HTML widgets and plugins that permit the insertion of arbitrary JavaScript and other code.
After being XOR-encoded, the JavaScript code is decoded and utilized to run a JavaScript file hosted on a remote server. This allows redirection to be made to a traffic distribution system (TDS) run by VexTrio, but only in ...

