Malware

Hacked WordPress sites harnessed in global cybercrime campaign

Information-stealing malware, ransomware, and cryptominers have been distributed through more than 100 breached WordPress sites around the world as part of the new ShadowCaptcha cybercrime campaign, which involves ClickFix social engineering and multiple living-off-the-land binaries, reports The Hacker News.

Illicit JavaScript code injected into the hacked WordPress sites facilitate redirection to bogus Cloudflare or Google CAPTCHA pages that use either the Windows Run dialog or prompts the saving and execution of the webpage as an HTML Application, with the former resulting in the delivery of the Rhadamanthys and Lumma infostealers and the latter leading to the deployment of Epsilon Red ransomware, according to researchers from the Israel National Digital Agency. XMRig-based cryptominers were deployed in other ShadowCaptcha campaigns. "ShadowCaptcha shows how social-engineering attacks have evolved into full-spectrum cyber operations. By tricking users into running built-in Windows tools and layering obfuscated scripts and vulnerable drivers, operators gain stealthy persistence and can pivot between data theft, crypto mining, or ransomware," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds