News: 1652414953

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Anatomy of a campaign to inject JavaScript into compromised WordPress sites

(2022/05/13)


A years-long campaign by miscreants to insert malicious JavaScript into vulnerable WordPress sites, so that visitors are redirected to scam websites, has been documented by reverse-engineers.

An [1]investigation by analysts at Sucuri into malware found on WordPress installations revealed a much larger and ongoing campaign that last month, we're told, hijacked more than 6,600 websites. The team has seen a spike in complaints this month related to the intrusions, according to analyst Krasimir Konov.

"The websites all shared a common issue — malicious JavaScript had been injected within their website's files and the database, including legitimate core WordPress files," [2]Konov wrote .

[3]

Those included such files as ./wp-includes/js/jquery/jquery.min.js and ./wp-includes/js/jquery/jquery-mgrate.min.js. Essentially, miscreants are compromising websites, and then try to automatically inject their own malicious code into any .js files with jQuery in the filename.

[4]

[5]

They also used CharCode to obfuscate the malicious JavaScript and evade detection. The obfuscated software is active on every page that pulls in the vandalized jQuery library files, enabling the attacker to redirect the site's visitors to whatever destination they choose. And that's usually phishing pages, malware-laced downloads, ad banners, or even more redirects, we're told.

To do this, the malicious injection creates a new script element on the page with a domain of legendarytable[.]com as the source. The code from that domain calls out to second external domain – local[.]drakefollow[.]com – which calls out to another one, setting up a series of domains the visitor is sent through until they're redirected to a site of one of many different domains.

[6]Time for people to patch backup plugin for WordPress

[7]Ew, that's unsanitary: SEO plugin for WordPress would run arbitrary JavaScript inputs instead of scrubbing them

[8]Don't be a WordPress RCE-hole and patch up this XSS vuln, pronto

[9]Couldn't give a fsck about patching? Well, that's your WordPress website pwned, then

"At this point, it's a free for all," Konov wrote. "Domains at the end of the redirect chain may be used to load advertisements, phishing pages, malware, or even more redirects."

Before landing on the final destination page, some visitors are sent to a fake CAPTCHA page, which tries to trick them into subscribing to push notifications from the malicious site.

[10]

"If they click on the fake CAPTCHA, they'll be opted in to receive unwanted ads even when the site isn't open — and ads will look like they come from the operating system, not from a browser," he wrote.

"These sneaky push notification opt-in maneuvers also happen to be one of the most common ways attackers display 'tech support' scams, which inform users that their computer is infected or slow and they should call a toll-free number to fix the problem."

WordPress powers about 43 percent of the websites on the internet, according to [11]W3Techs , but that reach also makes it a popular target for bad actors. About [12]90 percent of the requests they get for cleaning up a website were related to WordPress, with malicious redirects being the result of some of the most common malware infections, Sucuri said.

[13]

"As new vulnerabilities in WordPress plugins are discovered, we anticipate that they will be caught up in the massive ongoing redirect campaign sending unsuspecting victims to fraudulent websites and tech support scams," they wrote. ®

Get our [14]Tech Resources



[1] https://sucuri.net/reports/2021-hacked-website-report/

[2] https://blog.sucuri.net/2022/05/massive-wordpress-javascript-injection-campaign-redirects-to-ads.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yn4sSMMB2hROzjK@UJ9kHwAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn4sSMMB2hROzjK@UJ9kHwAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn4sSMMB2hROzjK@UJ9kHwAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/02/21/in_brief_security/

[7] https://www.theregister.com/2020/07/17/all_in_one_seo_pack_javascript_sanitisation_vuln/

[8] https://www.theregister.com/2019/03/14/wordpress_rce_vuln_v_5_1_0_previous/

[9] https://www.theregister.com/2018/09/21/wordpress_flaws_attacked/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn4sSMMB2hROzjK@UJ9kHwAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://w3techs.com/technologies/details/cm-wordpress

[12] https://blog.sucuri.net/2019/03/hacked-website-trend-report-2018.html

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn4sSMMB2hROzjK@UJ9kHwAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Makes me yearn for GeoCities...

ShadowSystems

At least the crap you found there was merely annoying as all hell, not actively hostile to your browser. Your mind yes, but not your browser.

I shall go fire up an animated GIF of the Ally McBeal "dancing baby" with a midi clip to loop with it. It's more entertaining than mucking out the stalls that have stabled JS...

Re: Makes me yearn for GeoCities...

b0llchit

Eternal under construction GeoCities pages... I want my blink-tag back!

Re: Makes me yearn for GeoCities...

MJB7

Feast your eyes on https://www.benz-holz.de/ then.

I haven't used them for a couple of years, but they are an entirely legitimate business. They are one of my potential suppliers for firewood and wood-pellets.

(I suspect somebody's child threw the website together for them 20 years ago, and it hasn't been changed since.)

Re: Makes me yearn for GeoCities...

JamesTGrant

Loads very quickly!!! I’m disappointed it didn’t have a twinkly background - the peak of html prowess!!

"ads will look like they come from the operating system"

Pascal Monett

That itself would light up big warning signs in my mind.

Before Windows 1 0, no OS worthy of the name would ever pop up an ad (thanks, Nadella, brilliant idea you got there).

I pity the people who start using computers these days. There is so much to learn to avoid being scammed, hacked and otherwise hijinked.

I have 30 years of experience in PCs and Internet. Nobody is going to fool me with an email attachment, or with a link (all links are suspicious until I have checked). If you email me and claim to work for Microsoft but your reply doesn't go back to Microsoft, you're out. And no, I don't believe that Bill Gates will send me $100 if I resend this to 20 people. These rules and many more are things I have accumulated over the years and they serve me well, but if you're a newcomer, it's an avalanche of things you need to assimilate and that's on top of trying to get to grips with how Windows works.

I'd hate to enter the arena at this point in time.

Re: "ads will look like they come from the operating system"

Anonymous Coward

> Nobody is going to fool me with an email attachment, or with a link

Has anyone seen my "Famous Last Words" file?

THIS IS PLEDGE WEEK FOR THE FORTUNE PROGRAM

If you like the fortune program, why not support it now with your
contribution of a pithy fortunes, clean or obscene? We cannot continue
without your support. Less than 14% of all fortune users are contributors.
That means that 86% of you are getting a free ride. We can't go on like
this much longer. Federal cutbacks mean less money for fortunes, and unless
user contributions increase to make up the difference, the fortune program
will have to shut down between midnight and 8 a.m. Don't let this happen.
Mail your fortunes right now to "fortune". Just type in your favorite pithy
saying. Do it now before you forget. Our target is 300 new fortunes by the
end of the week. Don't miss out. All fortunes will be acknowledged. If you
contribute 30 fortunes or more, you will receive a free subscription to "The
Fortune Hunter", our monthly program guide. If you contribute 50 or more,
you will receive a free "Fortune Hunter" coffee mug ....