BleepingComputer reports that more than 2,000 WordPress websites were discovered by MalwareHunterTeam to have been injected with crypto drainers to facilitate automated fund exfiltration a month after nearly a thousand hacked sites were found by Sucuri to have been used to enable brute-force attacks against other sites.
BleepingComputer 報告稱,在 Sucuri 發現近千個被駭網站被用來對其他網站進行暴力攻擊之後的一個月,MalwareHunterTeam 發現超過 2,000 個 WordPress 網站被注入了加密貨幣流失器,以促進自動資金滲漏。
WordPress sites without the "haw" cookie were injected with malicious scripts from the same domain used in the campaign discovered by Sucuri that would prompt pop-up cryptocurrency scam ads, which when clicked would show support for the Coinbase, Ledger, MetaMask, Trust Wallet, and Safe Wallet wallets. All cryptocurrency wallet assets are then exfiltrated by crypto drainers once targets establish a connection between their wallets and the Web3 site.
沒有「haw」cookie 的WordPress 網站被注入了來自Sucuri 發現的活動中使用的同一網域的惡意腳本,這些腳本將提示彈出加密貨幣詐騙廣告,點擊廣告後將顯示對Coinbase、Ledger、MetaMask、Trust Wallet的支持和安全錢包錢包。一旦目標在其錢包和 Web3 網站之間建立連接,所有加密貨幣錢包資產就會被加密貨幣流失者竊取。
Such a development comes amid the increasing use of cryptocurrency drainers among threat actors, some of which have exploited artificial intelligence videos and accounts on X, formerly Twitter, to facilitate the distribution of malicious scripts.
這種發展是在威脅行為者越來越多地使用加密貨幣消耗者的背景下發生的,其中一些人利用 X(以前稱為 Twitter)上的人工智慧影片和帳戶來促進惡意腳本的分發。