Automatically translated.View original post

Hackers use over 2,000 Wordpress websites.

Hackers used over 2,000 Wordpress websites in the Krypto heist campaign and released ransomware.

According to a report by the website, Biggo Finance has mentioned the detection of a campaign using more than 2,000 hacked websites on Wordpress to release a variety of malware, ranging from Ransomware, Infostealer, and other malware. A research team from Check Point, a cybersecurity specialist, called the campaign StopAndProtect after one of the ransomware whose fake Captcha authentication system was used on the hacked website, leading to PowerShell scripting and embedding malware. The ClickFix model was detected in the last May. The research team said that the campaign was not based on any malware, but a toolkit of hackers working together.

After the victim entered the script and successfully ran the PowerShell command on the screen, it would lead to a download of the dialer malware that was written on the language. NET. This malware will contact the C2 or Command and Control server to download the second Loader. This malware will serve to determine if it is running on the Sandbox environment. If tested, it will be found that it is not running on the environment, it will download the real Payload file. Payload will be the following ransomware tool.

SilentEncryptor is used to encrypt files on the victim's machine.

NetworkShareScanner is used to spread malware to different devices connected to the victim's machine.

The VBS Spreader is used to spread malware to the network (Network) connected to the victim's machine.

LockScreen is used to lock screens and display ransom messages (Ransom Note).

SimpleChatProxy is a chat program for victims to contact and talk to hackers.

SilentDataCollector is used to record the driver list of the encrypted victim and then send it back to the C2 server.

In addition, an anonymous version of the Infostealer malware has been found to be used. Keylogging has been added if the email address is detected, the ability to collect data from the Whatsapp chat application, and the Screenshot every 30 seconds. This campaign may not always lead to the installation of the above ransomware. Many times, it is only by using this Infostealer malware to steal data from the victim machine.

As for the website, a research team review found that most of the hacked websites were obsolete versions of Wordpress, as well as websites with vulnerable plug-ins. For example, some of the sites in this case were also websites running on the 2021 version of Wordpress. 2021), which makes the site vulnerable to more than 70 security vulnerabilities. These hacked websites perform three functions: use to deposit (Host) malware, serve as C2 server to send commands to malware, and use as a deposit of logs of malware that have been smuggled out from the victim's machine (Exfiltration).

By controlling that website, hackers install plug-ins with the upload of genus compressed files. The internal Zip has a PHP plug-in called uploader-installer.php. This plug-in creates a plug-in file in the website's wp-content / mu-plugins folder. This allows anyone with a password to upload files, including PHP files, to a Path on the website at will. When the website is modified as intended by the hackers, the plug-in will be stopped and removed to prevent detection. This is a plug-in uploading system to modify the page itself. Hackers can use it to upload a plug-in to make a ClickFix page. Trick the victim using the macOS to release malware theft. The information called Atomic Stealer inserts the victim's machine through the upload of a plug-in called activator.php. This plug-in will automatically delete itself after it is used.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Wordpress # freedomhack

5 days agoEdited to

... Read moreจากประสบการณ์ส่วนตัว ผมขอแชร์คำแนะนำสำหรับผู้ดูแลเว็บไซต์ Wordpress เพื่อป้องกันการถูกแฮกและใช้เป็นฐานปล่อยมัลแวร์แบบแคมเปญ StopAndProtect ที่รายงานนี้กล่าวถึง 1. อัปเดต Wordpress และปลั๊กอินอย่างสม่ำเสมอ เนื่องจากช่องโหว่ส่วนมากเกิดจากการใช้เวอร์ชันเก่าที่ล้าสมัย ซึ่งแฮกเกอร์มักเจาะผ่านช่องโหว่เหล่านี้ การติดตั้งรายการอัปเดตทันทีที่มีการปล่อยออกมาจะช่วยลดความเสี่ยงได้อย่างมาก 2. ใช้งานปลั๊กอินและธีมจากแหล่งที่น่าเชื่อถือเท่านั้น ปลั๊กอินที่ไม่มีการพัฒนาและตรวจสอบความปลอดภัยอาจกลายเป็นช่องทางให้แฮกเกอร์เข้าถึงระบบได้แบบไม่รู้ตัว 3. เพิ่มระบบยืนยันตัวตนแบบสองชั้น (2FA) ตั้งแต่ส่วนผู้ดูแลเว็บไซต์และผู้ใช้ทั่วไปเพื่อลดความเสี่ยงจากการถูกเดารหัสผ่านหรือ phishing 4. ตรวจตราการทำงานของเว็บไซต์และติดตั้งระบบตรวจจับมัลแวร์ เช่น สแกนหาไฟล์ปลั๊กอินที่ถูกแอบแฝง และระบบแจ้งเตือนเมื่อพบความผิดปกติที่ไม่พึงประสงค์ 5. สำรองข้อมูลเว็บไซต์เป็นประจำและเก็บในที่ปลอดภัย เพื่อกรณีเกิดเหตุการถูกล็อกหน้าจอหรือไฟล์ถูกเข้ารหัส จะสามารถกู้คืนข้อมูลได้โดยไม่ต้องจ่ายค่าไถ่ นอกจากนี้ แคมเปญนี้ยังใช้เทคนิค CAPTCHA ปลอมซึ่งลักษณะเฉพาะคือจะหลอกให้เหยื่อเชื่อว่ากำลังทำการยืนยันตัวตน ซึ่งจริง ๆ แล้วเป็นการรันสคริปท์ PowerShell และฝังมัลแวร์ลงบนเครื่อง เพื่อป้องกันตัวเองไม่ได้ถูกตรวจจับ ถ้าผู้ใช้งานพบ CAPTCHA ที่ดูผิดปกติ หรือเว็บไซต์โหลดสิ่งที่ไม่คาดคิด ควรระมัดระวังและไม่ทำตามขั้นตอนนั้น สุดท้าย การรักษาความปลอดภัยไซเบอร์ต้องเริ่มจากความรู้และความตระหนักของผู้ใช้งาน การศึกษาข่าวสารและเทคนิคใหม่ ๆ เกี่ยวกับมัลแวร์และช่องโหว่ จะช่วยให้เราสามารถรับมือกับภัยคุกคามเหล่านี้ได้อย่างมีประสิทธิภาพมากขึ้นรวมถึงลดความเสียหายที่อาจเกิดขึ้นจริงได้มากทีเดียว