• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

February 5, 2026

10 Hidden iPhone Features You’re Missing in iOS 26

February 4, 2026

Apple Watch Ultra 3 review: Incremental, but still superb

February 4, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Tech News»Hackers are using fake WordPress DDoS pages to launch malware
Tech News

Hackers are using fake WordPress DDoS pages to launch malware

August 23, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Hackers are using fake WordPress DDoS pages to launch malware
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers are pushing the distribution of harmful malware by way of WordPress web sites by bogus Cloudflare distributed denial of service (DDoS) safety pages, a brand new report has discovered.

As reported by PCMag and Bleeping Laptop, web sites based mostly on the WordPress format are being hacked by risk actors, with NetSupport RAT and a password-stealing trojan (RaccoonStealer) being put in if victims fall for the trick.

DailyTech Graphic

Cybersecurity agency Sucuri detailed how hackers are breaching WordPress websites that don’t have a powerful safety basis to be able to implement JavaScript payloads, which in flip showcase pretend Cloudflare safety DDoS alerts.

As soon as somebody visits one among these compromised websites, it’ll direct them to bodily click on a button to be able to affirm the DDoS safety verify. That motion will result in the obtain of a ‘security_install.iso’ file to 1’s system.

From right here, directions ask the person to open the contaminated file that’s disguised as a program known as DDOS GUARD, along with coming into a code.

One other file, security_install.exe, is current as effectively — a Home windows shortcut that executes a PowerShell command by way of the debug.txt file. As soon as the file is opened, NetSupport RAT, a well-liked distant entry trojan, is loaded onto the system. The scripts that run as soon as they’ve entry to the PC may also set up and launch the Raccoon Stealer password-stealing trojan.

Initially shut down in March 2022, Raccoon Stealer made a return in June with a variety of updates. As soon as efficiently opened on a sufferer’s system, Raccoon 2.0 will scan for passwords, cookies, auto-fill knowledge, and bank card particulars which might be saved and saved on internet browsers. It may additionally steal information and take screenshots of the desktop.

See also  Samsung says the Galaxy S23 protects against malware hidden in image attachments

As highlighted by Bleeping Laptop, DDoS safety screens are beginning to turn into the norm. Their objective is to guard web sites from malicious bots trying to disable their servers by flooding them with visitors. Nonetheless, it appears hackers have now discovered a loophole to make use of such screens as a disguise to unfold malware.

With this in thoughts, Sucuri advises WordPress admins to have a look at its theme information, which is the place risk actors are concentrating their efforts. Moreover, the safety web site stresses that ISO information gained’t be concerned with DDoS safety screens, so make sure you not obtain something of the type.

Hacking, malware, and ransomware exercise have turn into more and more widespread all through 2022. For instance, a hacking-as-a-service scheme gives the flexibility to steal person knowledge for simply $10. As ever, be sure to reinforce your passwords and allow two-factor authentication throughout all of your units and accounts.

Editors’ Selection











Source link

DDoS Fake hackers launch malware pages WordPress
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Beware of Hackers Posing as Apple Support

July 11, 2025

Apple to Launch Apple Intelligence in China amid US Concerns

June 18, 2025

FBI Says Hackers Now Targeting Connected Devices in Your Home

June 11, 2025

Five New Games Launch on Apple Arcade, Four More on the Way on July 3

June 6, 2025
Add A Comment

Comments are closed.

Editors Picks

5 Ways Finding Your Workstyle Can Improve Your Wellbeing

December 12, 2022

Ex-Apple engineers raise $7.5M for new Seattle data storage startup – Startup

January 9, 2023

Portland Trail Blazers end jersey sponsorship with Seattle crypto startup StormX – Startup

October 2, 2022

Chargebacks911 adopts AI to boost dispute resolution system three-fold

July 2, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

10 Hidden iPhone Features You’re Missing in iOS 26

Apple Watch Ultra 3 review: Incremental, but still superb

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.