Advertisement
Top
image credit: Pixabay

Over 1 Million WordPress Sites Infected by Balada Injector Malware Campaign

April 10, 2023

Category:

Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware called Balada Injector since 2017.

The massive campaign, per GoDaddy’s Sucuri, “leverages all known and recently discovered theme and plugin vulnerabilities” to breach WordPress sites. The attacks are known to play out in waves once every few weeks.

“This campaign is easily identified by its preference for String.fromCharCode obfuscation, the use of freshly registered domain names hosting malicious scripts on random subdomains, and by redirects to various scam sites,” security researcher Denis Sinegubko said.

Read More on The Hacker News