Thousands of WordPress websites hacked via plugin looking to steal user data

Estimated read time 2 min read



A new variant of the infamous ClearFake (AKA ClickFix) malware has been detected in the wild, and has already managed to compromise thousands of WordPress websites.

Researchers from GoDaddy claim to have spotted a variant of this campaign, which installs malicious plugins to sites on the website builder. The threat actors would use the credentials stolen elsewhere (or bought on the black market) to log into the website’s WordPress admin account, and install a seemingly benign plugin.



Source link

You May Also Like

More From Author

+ There are no comments

Add yours