"Long-Running Balada Injector Malware Campaign Infects Over 1 Million WordPress Sites"

1 min read
Source: The Hacker News
"Long-Running Balada Injector Malware Campaign Infects Over 1 Million WordPress Sites"
Photo: The Hacker News
TL;DR Summary

Over one million WordPress websites have been infected by the Balada Injector malware campaign since 2017, which exploits known and recently discovered theme and plugin vulnerabilities. The malware allows for the generation of fake WordPress admin users, harvests data stored in the underlying hosts, and leaves backdoors for persistent access. The attacks are engineered to read or download arbitrary site files and search for tools like adminer and phpmyadmin. WordPress users are recommended to keep their website software up-to-date, remove unused plugins and themes, and use strong WordPress admin passwords.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

84%

57790 words

Want the full story? Read the original article

Read on The Hacker News