- Marie Kondo’s online store slammed for selling clutter-worthy products 2 Years Ago
- People are rallying against toxic masculinity on International Men’s Day Today 4:42 PM
- Reddit wants to stop its pro-Trump forum from outing the alleged whistleblower Today 3:38 PM
- White woman calls cops on man who said he was visiting aunt with his kids Today 3:12 PM
- ‘The Stranded’ is a flawed yet addictive blend of ‘Degrassi’ and ‘Lost’ Today 2:45 PM
- The ‘gonna tell my kids’ meme is revisionist history at its most absurd Today 2:24 PM
- Redditor asks former burglars to give home security tips Today 2:18 PM
- Facebook-Breitbart partnership under fire in wake of new Stephen Miller emails Today 2:00 PM
- John Krasinski under fire after praising the CIA Today 1:46 PM
- Conservatives melt down after Chick-fil-A says it will stop donating to anti-LGBTQ orgs Today 1:33 PM
- ‘Honey Boy’ is an experimental look at channeling trauma Today 1:28 PM
- Disney+ now allows users to resume and restart content Today 11:42 AM
- New York sues JUUL for marketing to teenagers Today 11:34 AM
- The new ‘Discworld’ TV series just gender-flipped several major characters Today 10:54 AM
- David Fincher is doing a ‘Chinatown’ prequel series, naturally Today 10:43 AM
Hackers have targeted more than 2,000 WordPress websites to steal login credentials and tax visitors’ computers to mine cryptocurrency, researchers at security firm Sucuri discovered recently. WordPress is the one of the most popular content management systems (CMS), powering more than 25 percent of the websites on the internet, which means more websites might be at risk.
What we know about the attacks
Using this method, the attackers have managed to infect the pages of targeted websites with a keylogger, a malware the records keystrokes and sends them to the attacker’s server. This enables the hackers to steal all data entered in the website’s forms, including the login credentials of the administrator and other users.
The hackers have separately infected the WordPress frontend with CoinHive, an in-browser cryptojacker that targets the website’s visitors. CoinHive secretly uses the CPU of visitors to mine cryptocurrency for the attackers. If your website is infected, visitors will feel a sudden slowing down of their computers and smartphones. Cryptocurrency miners also drain smartphone batteries.
Sucuri did not say how the attackers managed to infect the websites. But such attacks usually occur on websites running older versions of WordPress (the current version is 4.9.2) or containing insecure plugins. WordPress has a very popular market for plugins and extensions. The official WordPress website hosts more than 50,000 plugins, and thousands of others can be acquired from other sources. These plugins are often poorly secured, containing exploitable vulnerabilities.
In December 2017, Sucuri found a similar attack that affected more than 5,500 websites. The domain hosting that attack (cloudflare[.]solutions) has long since been disabled. However, as researchers from Sucuri point out, the reinfection rate shows that there are still many sites that have failed to properly protect themselves after the original infection. “It’s possible that some of these websites didn’t even notice the original infection,” the blog post reads. Future attacks might infect more websites.
How to protect yourself
The first step to prevent your WordPress blog from being infected is to make sure you’re running the latest version of the engine and plugins. WordPress.com-hosted websites are automatically updated. If you’re using another hosting service, WordPress will warn you if a new version is available when you log in to your dashboard.
Updates will protect you from future attacks. To make sure your WordPress installation hasn’t already been infected, you must scan core files and database tables for recent and suspicious modifications and return them to their original version. The process isn’t trivial, but Sucuri has a page that guides you through the steps to find and remove infections.
If you don’t run a WordPress website but are worried about browsing to an infected website that will drain your CPU and battery to fill the pockets of anonymous hackers, you can install NoCoin, a browser extension that prevents cryptocurrency miners from running on your machine.
Ben Dickson is a software engineer and founder of TechTalks. His work has been published by TechCrunch, VentureBeat, the Next Web, PC Magazine, Huffington Post, and Motherboard, among others.