Threat Advisory

Hackers target WordPress with browser enabled brute force password assaults

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A widespread threat targeting WordPress sites has emerged, where hackers are deploying scripts to exploit unsuspecting visitors browsers for bruteforcing passwords on other websites. Initially recognized by cybersecurity firm, the campaign originated from compromised WordPress sites previously exploited to inject crypto wallet drainer scripts. However, the threat actor behind the attacks pivoted to utilizing these sites to distribute malicious code that commandeers visitors browsers, engaging them in brute force attacks aimed at compromising other WordPress sites. This represents a significant escalation in the tactics employed by threat actors, posing a serious risk to the security of WordPress site owners and their users.[/subscribe_to_unlock_form]

Summary:

A widespread threat targeting WordPress sites has emerged, where hackers are deploying scripts to exploit unsuspecting visitors browsers for bruteforcing passwords on other websites. Initially recognized by cybersecurity firm, the campaign originated from compromised WordPress sites previously exploited to inject crypto wallet drainer scripts. However, the threat actor behind the attacks pivoted to utilizing these sites to distribute malicious code that commandeers visitors browsers, engaging them in brute force attacks aimed at compromising other WordPress sites. This represents a significant escalation in the tactics employed by threat actors, posing a serious risk to the security of WordPress site owners and their users.[emaillocker id="1283"]

The technical aspect of this threat involves the injection of malicious scripts into compromised WordPress sites, which, when visited by users, quietly load scripts from a specified domain. These scripts then orchestrate the browser-based brute force attacks, sending requests to the attacker's server to retrieve tasks for attempting login credentials on other websites. The attacker utilizes a JSON file to supply parameters for the brute force attack, including the website URL, account name, and batches of passwords to try. Through this mechanism, the attacker clandestinely leverages the processing power of unwitting visitors' browsers to systematically test multiple passwords, potentially gaining unauthorized access to targeted WordPress sites.

In conclusion, the transition from injecting crypto wallet drainer scripts to deploying browser-based brute force attacks underscores the evolving sophistication of threat actors in the WordPress ecosystem. This shift indicates a strategic move towards stealthier tactics aimed at building a larger network of compromised sites for future malicious activities. The adoption of browser-based bruteforce attacks not only highlights the adaptability of cybercriminals but also emphasizes the critical importance of proactive security measures for WordPress site owners to mitigate the risk of exploitation and safeguard their online assets and user data.

Threat Profile:

References:

The following reports contain further technical details:

https://blog.sucuri.net/2024/03/from-web3-drainer-to-distributed-wordpress-brute-force-attack.html

[/emaillocker]
crossmenu