BleepingComputer reports that more than 2,000 WordPress websites were discovered by MalwareHunterTeam to have been injected with crypto drainers to facilitate automated fund exfiltration a month after nearly a thousand hacked sites were found by Sucuri to have been used to enable brute-force attacks against other sites.
BleepingComputer 报告称,在 Sucuri 发现近千个被黑网站被用来对其他网站进行暴力攻击之后的一个月,MalwareHunterTeam 发现超过 2,000 个 WordPress 网站被注入了加密货币流失器,以促进自动资金渗漏。
WordPress sites without the "haw" cookie were injected with malicious scripts from the same domain used in the campaign discovered by Sucuri that would prompt pop-up cryptocurrency scam ads, which when clicked would show support for the Coinbase, Ledger, MetaMask, Trust Wallet, and Safe Wallet wallets. All cryptocurrency wallet assets are then exfiltrated by crypto drainers once targets establish a connection between their wallets and the Web3 site.
没有“haw”cookie 的 WordPress 网站被注入了来自 Sucuri 发现的活动中使用的同一域的恶意脚本,这些脚本将提示弹出加密货币诈骗广告,点击该广告后将显示对 Coinbase、Ledger、MetaMask、Trust Wallet 的支持和安全钱包钱包。一旦目标在其钱包和 Web3 网站之间建立连接,所有加密货币钱包资产就会被加密货币流失者窃取。
Such a development comes amid the increasing use of cryptocurrency drainers among threat actors, some of which have exploited artificial intelligence videos and accounts on X, formerly Twitter, to facilitate the distribution of malicious scripts.
这种发展是在威胁行为者越来越多地使用加密货币消耗者的背景下发生的,其中一些人利用 X(以前称为 Twitter)上的人工智能视频和帐户来促进恶意脚本的分发。