A malware campaign designed to steal financial information and log-in credentials for a variety of popular online services has been secretly endangering Mexican users since at least 2013, researchers from Kaspersky Lab's Global Research & Analysis Team (GReAT) are warning.
A URL shortener, a fake plug-in and a malicious popuplink.js file are the three key ingredients found in a WordPress website infection campaign that since July has been redirecting victimized site visitors to various scam and ad sites.
The university discovered the intrusion by an unauthorized third party on the day after it first occurred, but only realized data had been breached through a report from outside security investigators on July 31.
Researchers have linked a newly discovered downloader malware to the Necurs botnet, after it was observed in a large email spam campaign targeting mostly financial organizations.