Threat Advisory

Massive Balada Injector campaign attacking WordPress sites

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A continuous campaign that exploits all known and recently found theme and plugin vulnerabilities to inject a Linux backdoor known as Balad. Over one million WordPress websites are compromised by this malware. The campaign started in 2017 and primarily tries to lure users to fake tech help pages, false lottery winnings, and push notification scams.[/subscribe_to_unlock_form]

Summary:

A continuous campaign that exploits all known and recently found theme and plugin vulnerabilities to inject a Linux backdoor known as Balad. Over one million WordPress websites are compromised by this malware. The campaign started in 2017 and primarily tries to lure users to fake tech help pages, false lottery winnings, and push notification scams.[emaillocker id="1283"]

According to researchers, Balada Injector attacks happen once a month and each one uses a recently registered domain name to avoid blocking lists. Often, the malware targets freshly discovered flaws and creates unique attack routines to get around them. Siteurl hacks, HTML injections, database injections, and random file injections are among the injection techniques that researchers have seen over the years. Because of the large number of attack vectors, duplicate site infections have also been produced, with succeeding waves focusing on vulnerable sites.

Balada's scripts concentrate on extracting confidential data from configuration files, such as database credentials, so even if the site owner cleans up the infection and updates their add-ons, the threat actor retains access. Additionally, the campaign looks for databases and backup archives, access logs, debug information, and files that may contain sensitive data. According to researchers, the threat actor updates the list of targeted files frequently. Adminer and phpMyAdmin are two examples of database management tools that the malware checks for. These tools could be used to create new admin users, extract data from the website, or inject persistent malware into the database if they are vulnerable or misconfigured. When there are no direct entry points, the attackers try brute-forcing the admin password.

To accomplish cross-site infections, the injectors then look for websites that have the same server account and file permissions, and they search those sites for readable directories, starting with higher-privileged folders. With only a few numbers of injectors to handle, this strategy enables threat actors to quickly breach multiple sites at once and distribute their backdoors. Experts point out that because there are so many different infection vectors, there is no one set of guidelines administrators can follow in order to neutralize Balada Injector attacks.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017/

[/emaillocker]
crossmenu