Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Friday November 08 2019, @12:46PM   Printer-friendly
from the watch-what-you-plug-in dept.

Submitted via IRC for soylent_red

WordPress Admins Infect Their Sites With WP-VCD via Pirated Plugins

WordPress sites have been the target of a highly active malicious campaign that infects them with a malware dubbed WP-VCD that hides in plain sight and quickly spreads to the entire website.

The group of hackers behind it have also made sure that their malicious payload is also very hard to get rid of once it manages to compromise a site. To make things worse, the malware is also designed to scan its way through the hosting server and infect any other WordPress sites it finds.

WP-VCD is spread by the most active malicious campaign impacting WordPress sites as of late, with the Wordfence threat intelligence team that took a closer look at it associating "individual WP-VCD malware samples with a higher rate of new infections than any other WordPress malware since August 2019."

The malware is also "installed on more new sites per week than any other malware in recent months" and "the campaign shows no signs of slowing down."

This is quite remarkable given that the malware has been doing rounds for more than two years, with the first publicly reported case of a WP-VCD infection going as far as February 2017, and users reporting infections and asking for advice on how to get rid of them on the WordPress Support forum [1, 2, 3, 4, 5] and in various other places on the Internet. [1, 2, 3]


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1, Touché) by Anonymous Coward on Friday November 08 2019, @02:26PM (1 child)

    by Anonymous Coward on Friday November 08 2019, @02:26PM (#917859)

    In this case, the webmasters are infecting their own sites by downloading and installing illegitimate versions of normally paid plugins from shady sites

    But. But. Software *wants* to be free.

    Starting Score:    0  points
    Moderation   +1  
       Touché=1, Total=1
    Extra 'Touché' Modifier   0  

    Total Score:   1  
  • (Score: 4, Insightful) by barbara hudson on Friday November 08 2019, @03:21PM

    by barbara hudson (6443) <barbara.Jane.hudson@icloud.com> on Friday November 08 2019, @03:21PM (#917882) Journal
    Well, it's one way to get paid. The owners of the plugins can create copies with miners, etc., and upload them to shady sites where pirates can download them, so like the old Fram commercial - "you can pay me now or pay me later."
    --
    SoylentNews is social media. Says so right in the slogan. Soylentnews is people, not tech.