Summary:
According to the researchers 30 vulnerabilities in several outdated WordPress plugins and themes have been exploited by the unknown Linux malware to inject malicious JavaScript. The malwares primary job is to break into WordPress sites using a series of hardcoded attacks that are executed one after another until one of them succeeds. Then the infected pages act as redirectors to a location of an attacker’s choice. These redirections can be used to help evade detection and blocking in phishing, malware distribution, and malvertising operations.[/subscribe_to_unlock_form]
Summary:
According to the researchers 30 vulnerabilities in several outdated WordPress plugins and themes have been exploited by the unknown Linux malware to inject malicious JavaScript. The malwares primary job is to break into WordPress sites using a series of hardcoded attacks that are executed one after another until one of them succeeds. Then the infected pages act as redirectors to a location of an attacker’s choice. These redirections can be used to help evade detection and blocking in phishing, malware distribution, and malvertising operations.[emaillocker id="1283"]

Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]