Password-cracking botnet has taken over WordPress sites to attack using the visitor's browser

Botnet
(Image credit: Shutterstock)

As reported by Ars Technica, cybersecurity researcher Denis Sinegubko has been monitoring ongoing website hacking activities for a long time. Now, he has identified a major pivot from crypto wallet drainers to brute-force password-cracking attacks on WordPress sites. Why is this happening, what does it mean, and what can you, as an end user, do? We'll dive into all of the need-to-know information right away below.

First, let's talk "Why." Earlier in February, Sinegubko, writing for Sucuri's blog, discussed an increase in "web3 crypto malware," particularly malware used to inject crypto drainers into existing sites or use phishing sites for the same purpose.

Latest Videos FromTom's Hardware
Christopher Harper
Contributing Writer

Christopher Harper has been a successful freelance tech writer specializing in PC hardware and gaming since 2015, and ghostwrote for various B2B clients in High School before that. Outside of work, Christopher is best known to friends and rivals as an active competitive player in various eSports (particularly fighting games and arena shooters) and a purveyor of music ranging from Jimi Hendrix to Killer Mike to the Sonic Adventure 2 soundtrack.

  • CmdrShepard
    Ah, Wordpress... the gift that keeps giving.
    Reply
  • Vanderlindemedia
    It's time devs, webdesigners, majority of folks, stop using wordpress, and look for serious alternatives.

    I host websites as a profession other then designing or doing marketing. One thing i noticed is the amount of resources required, just to run wordpress, and just to spawn up one page.

    As a countermeasure you need tough tools like litespeed cache, redis object cache, and additional use of Cloudlinux in order to cap or limit users whenever they exceed their resources in such attacks. Let alone the sheer amount of updates that can brick your website just like that.

    Roughly 50 to 60% by now of total or complete server traffic or consumed resources, is purely wordpress or noise caused by it. It's a terrible product from a technical standpoint.
    Reply
  • Alvar "Miles" Udell
    NoScript should be used on -any- site.
    Reply
  • EduAAA
    whatever, share the leaked hot chick porn pictures
    Reply
  • digitalgriffin
    CmdrShepard said:
    Ah, Wordpress... the gift that keeps giving.
    The problem isn't word press. It's people using weak passwords. This can happen to any website with file sharing.
    Reply