Security News > 2021 > November > WordPress sites are being hacked in fake ransomware attacks

WordPress sites are being hacked in fake ransomware attacks
2021-11-16 17:35

A new wave of attacks starting late last week has hacked close to 300 WordPress sites to display fake encryption notices, trying to trick the site owners into paying 0.1 bitcoin for restoration.

The researchers discovered that the websites had not been encrypted, but rather the threat actors modified an installed WordPress plugin to display a ransom note and countdown when.

In addition to displaying a ransom note, the plugin would modify all the WordPress blog posts and set their 'post status' to 'null,' causing them to go into an unpublished state.

As for the plugin seen by Sucuri, it was Directorist, which is a tool to build online business directory listings on sites.

Sucuri has tracked approximately 291 websites affected by this attack, with a Google search showing a mix of cleaned-up sites and those still showing ransom notes.

All of the sites seen by BleepingComputer in search results use the same 3BkiGYFh6QtjtNCPNNjGwszoqqCka2SDEc Bitcoin address, which has not received any ransom payments.


News URL

https://www.bleepingcomputer.com/news/security/wordpress-sites-are-being-hacked-in-fake-ransomware-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159