Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks
Mar 07, 2024
Vulnerability / Web Security
 Threat actors are conducting brute-force attacks against WordPress sites by leveraging malicious JavaScript injections, new findings from Sucuri reveal.  The attacks, which take the form of distributed brute-force attacks, "target WordPress websites from the browsers of completely innocent and unsuspecting site visitors," security researcher Denis Sinegubko  said .  The activity is part of a  previously documented attack wave  in which compromised WordPress sites were used to inject crypto drainers such as Angel Drainer directly or redirect site visitors to Web3 phishing sites containing drainer malware.  The latest iteration is notable for the fact that the injections – found on  over 700 sites  to date – don't load a drainer but rather use a list of common and leaked passwords to brute-force other WordPress sites.   The attack unfolds over five stages, enabling a threat actor to take advantage of already compromised websites to launch distributed brute-force ...