Automatically translated.View original post

A group of GrayCharlie hackers shot JavaScript. Put it...

A group of GrayCharlie hackers fired JavaScript into the Wordpress website to release NetSupport RAT malware.

Website building platforms like Wordpress, while popular, are always targeted by hackers for hacking or embedding malware, and this time websites built on Wordpress are targeted again.

According to a report by the website, Cyber Security News mentioned the detection of a GrayCharlie hacker campaign, which launched an attack on a Wordpress-based website in 2023 with the implantation of an embeded JavaScript script on the site with the aim of releasing a malware type that remotely controls the victim's machine, or a RAT (Remote Access Trojan) called NetSupport RAT, and a malware type that steals data from the victim's machine, or an Infostealer named Stealc, as well as in the latter, another RAT type of malware was introduced into the campaign.

The technique used by the hacker group is to write a script to "tag" to the Document Object Model (DOM) on the target website. This tag points to JavaScript outside the web hosted on the hacker's server. If the victim opens a website that has been attacked by the hacker, the script checks which web browser and operating system the victim is using. If the script matches the script, it sends the victim to the next step, it attacks the victim by using a fake error alert to trick the victim into running a malware installation command or ClickFix with a fake CaptCha, and another way. One is to trick the victim into installing a fake web browser update, both of which lead to the installation of both malware.

A review by a research team from Recorded Future, an expert company developing cyber detectors, found that the backyard infrastructure, or Backend Infrastructure of the campaign, is using MivoCloud's cloud services and HZ Hosting Ltd's hosting services as part of the infrastructure system, and that the cluster (Cluster), the control server (C2 or Command and Control) of NetSupport RAT malware has been used to release deware (Deploy) since 2025. 2568) By examining the naming method of the TLC Certificate, License Key, and Serial Number associated with this infrastructure. In the area of communication of the C2 server, it is contacted through TCP port 443 with the SSH protocol. It allows data traffic to be camouflaged. It is not noticeable.

In the field of work of this campaign, the details are different in how to deceive the victims:

Fake Web Browser Update Scam: After the victim has logged into the website and installed a fake web browser update in JavaScript format, the WScript script will run PowerShell to download and unload the malware (Payload) files of the NetSupport RAT malware to the AppData folder.

ClickFix: After the victim places the command on Run and presses Enter, it downloads the Batch script file (.Bat) and then writes the Key Run in the Registry to guarantee that the malware will continue to work on the system (Persistence) every time it is rebooted, then contacts the C2 server, runs the System Reconnaissance tool, and ultimately releases the SectopRAT malware payload.

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # Drug sign with lemon8

3/21 Edited to

... Read moreจากประสบการณ์ส่วนตัวในการดูแลเว็บไซต์ Wordpress ผมพบว่าแม้ Wordpress จะเป็นเครื่องมือยอดนิยมในการสร้างเว็บ แต่ก็มีจุดอ่อนสำคัญคือการตกเป็นเป้าของแฮกเกอร์ที่ใช้ช่องโหว่ต่างๆ ฝังมัลแวร์ เช่นกรณีแคมเปญของกลุ่ม GrayCharlie ที่โจมตีผู้ใช้ Wordpress ด้วยการฝัง JavaScript แอบแฝงบนหน้าเว็บ ซึ่งเมื่อผู้ใช้งานเปิดเว็บไซต์ที่ติดสคริปต์ดังกล่าว ระบบจะตรวจสอบเว็บเบราว์เซอร์และระบบปฏิบัติการของเหยื่อ ก่อนหลอกให้ติดตั้งมัลแวร์ผ่านการอัปเดตเบราว์เซอร์ปลอม หรือ CaptCha ปลอม เทคนิคนี้ทำให้ผู้ใช้งานหลงเชื่อและยอมลงมือทำตามขั้นตอนติดตั้งมัลแวร์อย่างไม่รู้ตัว การโจมตีแบบนี้จึงเรียกได้ว่าแฝงตัวอย่างแนบเนียนและมีความซับซ้อนสูง รวมถึงยังมีการใช้เซิร์ฟเวอร์ควบคุมของแฮกเกอร์ที่ตั้งอยู่บนคลาวด์ MivoCloud และ HZ Hosting Ltd เพื่อบริหารจัดการมัลแวร์ NetSupport RAT อีกด้วย สำหรับผู้ดูแลเว็บ Wordpress ผมขอแนะนำให้ตรวจสอบปลั๊กอิน และธีมอย่างสม่ำเสมอ รวมถึงอัปเดต Wordpress และส่วนเสริมต่างๆ ให้เป็นเวอร์ชันล่าสุดเสมอ เพื่อป้องกันช่องโหว่ที่จะถูกใช้โจมตี นอกจากนี้ควรใช้เครื่องมือสแกนมัลแวร์และเสริมความปลอดภัย เช่น การตั้งค่าไฟร์วอลล์เว็บแอปพลิเคชัน (WAF) และควบคุมการเข้าถึงไฟล์ที่สำคัญ ในฝั่งผู้ใช้งานทั่วไป หากพบข้อความแจ้งเตือนอัปเดตเว็บเบราว์เซอร์แบบผิดปกติ หรือแบบ CaptCha ที่ไม่น่าเชื่อถือ ควรหลีกเลี่ยงการติดตั้งและตรวจสอบแหล่งที่มาของการแจ้งเตือนเหล่านั้นก่อนทุกครั้ง เพราะมัลแวร์ NetSupport RAT มีความสามารถควบคุมเครื่องจากระยะไกลและขโมยข้อมูลที่สำคัญได้ หากเกิดการติดเชื้ออาจส่งผลเสียต่อตัวเครื่องและข้อมูลส่วนตัวอย่างรุนแรง ท้ายที่สุดแล้ว ความระมัดระวังและการอัปเดตความรู้ด้านความปลอดภัยไซเบอร์อย่างสม่ำเสมอ จะช่วยให้เราป้องกันและลดความเสี่ยงจากแคมเปญมัลแวร์เหล่านี้ได้อย่างมีประสิทธิภาพ

Related posts

SIEGEX is all CHEATERS & HACKERS😭
Why is this game full of cheaters and hackers and bugs🤷‍♀️ #siege #rainbowsixsiege #gaming #streamer #foryou
Phasma

Phasma

28 likes

scammers and hackers beware
Hudson
cercofhell

cercofhell

28 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

Hackers
How call of duty has me #call of duty #hacker #warzone
Stevie_Wonders

Stevie_Wonders

1 like

Kalebdavis19

Kalebdavis19

0 likes

Do you like hackers?
#hacker #hackers #tricked #fyp
Lil Conscious

Lil Conscious

38 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

A message to Minecraft hackers…
You should join the server #minecraft #gaming #fyp
BendersMC

BendersMC

13 likes

Ban Hackers
😃 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

4 likes

Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

273 likes

SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

424 likes

Bigfoot Super Hackers.
#manthoughts #hackers #laughoutloud #bigfootvlog #lifetips
Alien Hayes

Alien Hayes

11 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

1 like

Poor Belle ! #beauty & the beast salt shackers
Like why did they have to paint her face like that 😂😂🤣🤣 #new #beauty #beautyandthebeast #disney #salt #pepper #homegoods #finds #fyp #fypシ #trending #shop #shopping #shopwithme #fypage #explore #explorepage #reels #eleydencreations #content #contentcreator #creator
EleydenCreation

EleydenCreation

651 likes

Hackers suck
Fastcarracer36

Fastcarracer36

7 likes

Ban Hackers
Vinicius Jr 🇧🇷 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

1 like

Prayers for Jamaica 🇯🇲 — opening Hacker’s Slumber,
Cousin B

Cousin B

0 likes

Look world just locked my Facebook account cause I was. Sharing my video Look world these meth going to crazy again the 7th time February 16,2026 on my bingo app right now harassing me cause I'm listening to the video of court day Morehouse parish sheriff department officers and Mike Stone Tubb
glentrump359

glentrump359

2 likes

God, please unblock this android, hackers have in
Olga Ledbetter

Olga Ledbetter

37 likes

BREAKING: FBI Director Kash Patel’s Personal Email Reportedly Breached by Iran
BREAKING: FBI Director Kash Patel’s Personal Email Reportedly Breached by Iran-Linked Hackers ⸻ A shocking cybersecurity breach has reportedly exposed the personal email of FBI Director Kash Patel. Iran-linked hackers claim they accessed his Gmail account and leaked private content online. W
King media Roof Llc

King media Roof Llc

29 likes

warzone hackers be mad little babies
#cod #ps5 #gamergirl #warzone #fuckhackers
Twilightvile

Twilightvile

2 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Hackers hijacked antivirus features to install mal
Hackers hijacked antivirus features to install malware - here's what we know https://www.yahoo.com/tech/cybersecurity/articles/hackers-hijacked-antivirus-features-install-140500891.html #hackers #malware #cybersecurity #antivirus
angela1957

angela1957

1 like

SEPT WRAP UP PT 1.
september had me in a CHOKEHOLD y'all 😮‍💨 i read so much i have to break this into TWO PARTS 😂😂 • 47 books read (don't play with me •) • 19 new authors • multiple favorites that little binge had me blowing right past my 200 book goal, so you know i had to bump it up to 250 from messy d
LEXI 💓

LEXI 💓

32 likes

#yungblud
watch4hackers

watch4hackers

5 likes

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

Look world still on my YouTube channel right now removing my YouTube channel right now and on my Facebook account right now pausing my lives since 4:44 am these meth heads going crazy Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubb
glentrump359

glentrump359

0 likes

Hackers, AI and Cyberattacks
https://www.techradar.com/ai-platforms-assistants/if-hackers-can-use-ai-to-automate-massive-cyber-attacks-terminator-robots-are-the-least-of-our-problems #ai #hackers #cyberattacks #robots
angela1957

angela1957

2 likes

HACKERS IN THE BETA
Blackops 7 has hackers already…. #hacker #blackops7 #bo7
Goofstha

Goofstha

1 like

Ban Hackers
Heel to Heel Flick #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

0 likes

These Hackers on Marvel Rivals getting crazy!
#marvelrivals #twitchtv #followme #Hackers #marvelfunny
MisFit Miracles

MisFit Miracles

1 like

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

I urge you to go Google this. These Hackers starte
Hollywood

Hollywood

0 likes

These meth heads going crazy Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just locked my Facebook accounts right now for no reason y'all obsessed with me gay bitches unlocked my damn Facebook account
glentrump359

glentrump359

0 likes

Don’t trust everything you get through an email or text. #tiktokshop #hacks #hackers #tiktokshopaffiliate #fyp
NiaRose

NiaRose

0 likes

A rumor has been going around that Iranian hackers threatened to hack the U.S. credit system and boost everyone’s credit score. #fyp
iddy2707

iddy2707

2 likes

Wz hackers
Who misses Warzone tempo movement gameplay I feel like it was honestly peak. I don’t think the game will ever reach that level again. There are too worried about selling bundles rather than fixing the game #wargaming #streamer #fypシ゚viral #teamwipewarzone #hackers
Sauccyyyjgaming

Sauccyyyjgaming

0 likes

Which of these video games would you play?
Hkohles1gaming

Hkohles1gaming

1 like

Chinese Hackers Target Senior US Officials
China’s Salt Typhoon continues to target very senior US government official by intercepting phone calls and meta data in a continued cyber espionage campaign. #china #hackers #cybersecurity #salttyphoon
Lemon8er

Lemon8er

0 likes

WARNING TO 2.5B GMAIL USERS. Hackers are continuing to target you. Here’s what to do Follow @cybersecuritygirl for more tips #google #gmail #tips #news #techtips
Cybersecurity Girl

Cybersecurity Girl

496 likes

OH HACKERS & SHIPMENT
#codm #fypシ #camogrind #hacker #fyp
GlockitSuckit

GlockitSuckit

2 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Omg 😱 this app is becoming a bunch of hackers and
This app related to tik tok, why yall making it as a bunch of hackers and scammers WTH 🤦‍♀️ go somewhere else with your nonsense
ruthiyalvarez

ruthiyalvarez

2 likes

These hackers are serious
#robloxhoodgames #roblox #thabronx2💯 #NLMB #lemonfyp #robloxgames https://discord.gg/XkvWvPWj
nlmbthefamily

nlmbthefamily

1 like

hackers everywhere
#fortinite #fyp
Outro-7

Outro-7

0 likes

WARZONE HACKERS
Warzone is full hackers and call of duty does not care #warzone #hacker #memesdaily #memes🤣 #gaming
DUSTINMYRQ ™

DUSTINMYRQ ™

3 likes

Look world Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg rejecting all my followers on my Snapchat right now these meth heads going crazy frfr
glentrump359

glentrump359

4 likes

How to spy on your partner’s phone to catch them
Cheating #howtospyonyourcheatingpartner #2024 #viral #fypシ゚viral New York
Morgancyberhelp

Morgancyberhelp

47 likes

See more