Linux Backdoor Malware Targets WordPress Sites with Outdated, Vulnerable Themes and Plugins

Linux Backdoor Malware Targets WordPress Sites with Outdated, Vulnerable Themes and Plugins

Posted by WP Tavern on January 4, 2023 at 3:13 pm
kitty kitty CATegory News
Security researchers at Doctor Web, a security company focused on threat detection and prevention, have discovered a malicious Linux program that targets WordPress sites running outdated and vulnerable plugins and themes. The malware targets 32-bit versions of Linux, but it is also capable of running on 64-bit versions. It exploits 30 theme and plugin vulnerabilities to inject malicious JavaScript into websites, redirecting visitors to the attacker’s selected website. The report states that Doctor Webs’ analysis of the application revealed that “it could be the malicious tool that cybercriminals have been using for more than three years to carry out such attacks and monetize the resale of traffic, or arbitrage.” During this time, the tool has been updated to target more exploitable vulnerabilities. There are two versions of the malware – Linux.BackDoor.WordPressExploit.1 and Linux.BackDoor.WordPressExploit.2. Version 1 seeks to exploit vulnerabilities in popular plugins like WP GDPR Compliance, Easysmtp, WP Live Chat, and a dozen other free and commercial extensions. A few of these have been known to have frequent vulnerabilities and one was closed due to guideline violations but may still be active on some sites. An updated Version 2 has a different server address for distributing the malicious JavaScript and…

…Full post on WP Tavern
Read Full

Similar Posts

Leave a Reply