WordPress sites hacked in fake ransomware attacks

security threat
(Image credit: Shutterstock.com)

Security researchers have found that close to 300 WordPress websites have been defaced to display fake attack notices, in order to trick the site owners into paying 0.1 bitcoin (BTC) for restoration.

Accompanying the ransom demands were countdown timers that were added to create more panic and further arm twist the owners into paying the ransom.

The deception behind these attacks was discovered by cybersecurity firm Sucuri who was hired by one of the victims to perform incident response on the supposed attack.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

As soon as they began their investigation, the researchers discovered that the websites’ pages had not been encrypted, and that the notice was fake.

Clever deception

The researchers said that the “attack” had all the hallmarks of a genuine ransomware campaign, as it seemed to suggest that the website had been encrypted. While the demand sum of 0.1 BTC was considerably less than what is demanded in typical ransomware attacks, it still comes to over $6000, which is still a considerable amount of money.

“Before panicking and paying the ransom (or completely re-building their website from scratch) thankfully some website owners hired us to take a look,” writes Sucuri, who had tackled ransomware attacks on websites earlier. 

However, as soon as they looked inside the web server, they discovered that the files weren’t encrypted. Instead, the warning turned out to be a simple HTML page generated by a bogus WordPress plugin.

In addition to displaying the message and the timer, the plugin issued a simple SQL command to find any posts and pages that had the “publish” status, and changed it to “null,“ which would 404 all pages, and lend credibility to the fake attack.

The researchers however couldn’t determine if the attackers had brute forced the admin password, or had acquired the already-compromised login from the black market.

Want to build a website? Use one of these best WordPress hosting providers and build them with the help of these best WordPress website builders

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over 10,000 WordPress sites found showing fake Google browser update pages to spread malware
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
WordPress users targeted by devious new credit card skimmer malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
WordPress
Another top WordPress plugin found carrying critical security flaws
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand