BleepingComputer reports that more than 2,000 WordPress websites were discovered by MalwareHunterTeam to have been injected with crypto drainers to facilitate automated fund exfiltration a month after nearly a thousand hacked sites were found by Sucuri to have been used to enable brute-force attacks against other sites.
BleepingComputer는 Sucuri가 다른 사이트에 대한 무차별 대입 공격을 가능하게 하는 데 사용된 거의 천 개의 해킹된 사이트를 발견한 후 한 달 만에 MalwareHunterTeam이 자동 자금 유출을 용이하게 하기 위해 암호화 드레이너를 주입한 것으로 2,000개 이상의 WordPress 웹사이트를 발견했다고 보고했습니다.
WordPress sites without the "haw" cookie were injected with malicious scripts from the same domain used in the campaign discovered by Sucuri that would prompt pop-up cryptocurrency scam ads, which when clicked would show support for the Coinbase, Ledger, MetaMask, Trust Wallet, and Safe Wallet wallets. All cryptocurrency wallet assets are then exfiltrated by crypto drainers once targets establish a connection between their wallets and the Web3 site.
"haw" 쿠키가 없는 WordPress 사이트에는 Sucuri가 발견한 캠페인에 사용된 것과 동일한 도메인의 악성 스크립트가 주입되어 팝업 암호화폐 사기 광고를 표시하고, 이를 클릭하면 Coinbase, Ledger, MetaMask, Trust Wallet에 대한 지원이 표시됩니다. 및 Safe Wallet 지갑입니다. 모든 암호화폐 지갑 자산은 대상이 지갑과 Web3 사이트 사이에 연결을 설정하면 암호화폐 배수기에 의해 유출됩니다.
Such a development comes amid the increasing use of cryptocurrency drainers among threat actors, some of which have exploited artificial intelligence videos and accounts on X, formerly Twitter, to facilitate the distribution of malicious scripts.
이러한 발전은 위협 행위자들 사이에서 암호화폐 유출 장치의 사용이 증가하는 가운데 이루어졌으며, 이들 중 일부는 악성 스크립트 배포를 촉진하기 위해 X(이전에는 Twitter)의 인공 지능 비디오 및 계정을 악용했습니다.