BleepingComputer reports that more than 2,000 WordPress websites were discovered by MalwareHunterTeam to have been injected with crypto drainers to facilitate automated fund exfiltration a month after nearly a thousand hacked sites were found by Sucuri to have been used to enable brute-force attacks against other sites.
BleepingComputer の報告によると、ハッキングされた約 1,000 のサイトが他のサイトに対するブルートフォース攻撃を可能にするために使用されていたことが Sucuri によって発見されてから 1 か月後、2,000 を超える WordPress Web サイトが、自動資金流出を促進するために暗号通貨排出装置が注入されていたことが MalwareHunterTeam によって発見されました。
WordPress sites without the "haw" cookie were injected with malicious scripts from the same domain used in the campaign discovered by Sucuri that would prompt pop-up cryptocurrency scam ads, which when clicked would show support for the Coinbase, Ledger, MetaMask, Trust Wallet, and Safe Wallet wallets. All cryptocurrency wallet assets are then exfiltrated by crypto drainers once targets establish a connection between their wallets and the Web3 site.
「haw」Cookie を持たない WordPress サイトには、Sucuri が発見したキャンペーンで使用されたのと同じドメインから悪意のあるスクリプトが挿入され、仮想通貨詐欺のポップアップ広告が表示され、クリックすると Coinbase、Ledger、MetaMask、Trust Wallet のサポートが表示されます。 、およびSafe Walletウォレット。ターゲットがウォレットと Web3 サイト間の接続を確立すると、すべての暗号通貨ウォレット資産が暗号通貨排出者によって抜き取られます。
Such a development comes amid the increasing use of cryptocurrency drainers among threat actors, some of which have exploited artificial intelligence videos and accounts on X, formerly Twitter, to facilitate the distribution of malicious scripts.
このような開発は、脅威アクターの間で暗号通貨排出者の使用が増加している中で行われ、その一部は、悪意のあるスクリプトの配布を容易にするために、X (旧 Twitter) 上の人工知能ビデオやアカウントを悪用しています。