Thousands of WordPress sites hacked in scam campaign

(Image credit: Pixabay)

New research has revealed that over 2,000 WordPress sites have hacked as part of a campaign to redirect visitors to a number of scam sites which contain unwanted notification subscriptions, fake surveys, giveaways and even fake Adobe Flash downloads.

The security firm Sucuri first discovered the hacking campaign when its researchers detected attackers exploiting vulnerabilities in WordPress plugins. According to the firm's Luke Leal, CP Contact Form with PayPal and the Simple Fields plugins are being exploited but other plugins have likely also been targeted.

When an attacker exploits one of these vulnerabilities, it allows them to inject JavaScript that loads scripts from the sites admarketlocation and gotosecond2 directly into a site's theme. 

Once a visitor accesses a hacked site, the injected script will try to access two administrative URLs (/wp-admin/options-general.php and /wp-admin/theme-editor.php) in the background in order to inject additional scripts or to change WrodPress settings that will also redirect visitors. However, these URLs require administrative access so they will only work if an administrator is accessing the site.

Scam pages

The attackers have written their scripts so that visitors without administrative privileges will be redirected through a series of sites that will eventually lead them to various scam pages. These pages then tell users that they must subscribe to browser notifications in order to proceed.

Clicking on the allow button to enable notifications then redirects visitors to other scam sites pushing fake surveys, tech support scams and fake Adobe Flash Player updates.

Sucuri also discovered that the attackers had created fake plugin directories which are used to upload additional malware to the compromised sites. Leal provided further details on how the attackers created fake plugin directories in a blog post, saying:

“Another interesting find is the creation of fake plugin directories that contain further malware and can also be generated through the attacker’s abuse of /wp-admin/ features, namely uploading zip compressed files using the /wp-admin/includes/plugin-install.php file to perform the upload and unzipping of the compressed fake plugin into /wp-content/plugins/."

To see if your WordPress site has been hacked, Sucuri recommends using its free SiteCheck tool to scan for malicious content.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'