Fake WordPress Plugin Comes with Cryptocurrency Mining Function

- Advertisement -

Malicious plugins for WordPress websites are being used not just to maintain access on the compromised server but also to mine for cryptocurrency.

Researchers at website security company Sucuri noticed the number of malicious plugins increase over the past months. The components are clones of legitimate software, altered for nefarious purposes.

Normally, these fake plugins are used to give attackers access to the server even after the infection vector is removed. But they can include code for other purposes, too, such as encrypting content on a blog.

Double hedging

One of the plugins discovered by Sucuri to have a double purpose is a clone of “wpframework.” It was found in September and attackers used it to “gain and maintain unauthorized access to the site environment,” the researchers say.

It is unclear which plugin it impersonates, but one with this name exists in the WordPress public repository but its development seems to have stopped in 2011. Despite this, it still has more than 400 active installations.

Apart from scanning for functions that allow command execution at the server level and restricting this privilege to the botmaster, the plugin also carried code to run a Linux binary that mines for cryptocurrency.

When the researchers checked the referenced domain hosting the binary it was no longer active. However, the backdoor functionality of the component was still present.

The mining component was added to the Virus Total antivirus scanning platform on September 18 and is currently detected by 25 out of 56 engines.

Generating malicious plugins

Although Sucuri does not provide details about the reason for the increased frequency of malicious plugins, it is worth noting that creating them is far from being an effort.

Instead of creating a malicious WordPress plugin from scratch, attackers can modify the code of an existing one to include malicious components.

Additionally, automated tools exist that can generate a plugin with a name given by the attacker and lace it with an arbitrary payload, such as a reverse shell.

Furthermore, the web offers the necessary tutorial for low-skilled attackers to learn how to create these fake website components.

Sucuri advises webmasters to also check the additional site components when doing a malware cleanup since many times this procedure is limited to WordPress core files. Themes and plugins are often migrated without any prior scrutiny. This way, attackers maintain their grip on the new site through the backdoor planted in third-party extensions.

Source

Previous Articles:

- Advertisement -
- Advertisement -
- Advertisement -

Latest

Warren Slams Trump Stablecoin Bill: “Grift to Enrich Himself”

Senator Elizabeth Warren criticizes stablecoin legislation, claiming it enables President Trump to leverage his crypto project for personal enrichment.Warren specifically targets the Financial Innovation...

Trump Threatens “Larger Scale Tariffs” on EU, Canada Amid Trade Tensions

Former President Trump threatens larger import tariffs against EU and Canada if they collaborate to harm U.S. economic interests.Financial markets remain stable despite Trump's...

OpenAI’s revenue to surge to $12.7B amid rising Chinese AI challengers

OpenAI projects revenue growth from $12.7 billion in 2024 to $29.4 billion in 2025, despite not expecting positive cash flow until 2029.The company is...

Synthetix Founder Exposes Predatory Crypto Market Maker Tactics

Synthetix founder Kain Warwick revealed how crypto market makers have evolved from legitimate operations to manipulative entities charging projects up to $300,000 monthly during...

Court Dismisses Dfinity Lawsuit: ICP Investors’ Claims Expired

U.S. District Judge James Donato dismissed a class action lawsuit against Dfinity related to Internet Computer (ICP) tokens, citing time limitation issues.The lawsuit, filed...

US Senate Votes to Kill Biden-Era DeFi Tax Reporting Rule

US Senate passed a resolution with a 70-28 vote to repeal the IRS DeFi broker rule targeting crypto reporting.The resolution will next head to...

Russia Faces Energy Crisis, May Import Electricity from China

Russia faces severe energy shortages caused by the Ukraine war, Western sanctions, and cryptocurrency mining demand, transforming it from an energy exporter to a...

US Lawmakers Push Stablecoin Bill Forward in Trump’s Crypto Agenda

Republican lawmakers plan to advance stablecoin legislation and update the FIT 21 crypto framework within days.House Financial Services Crypto Subcommittee published a draft stablecoin...
- Advertisement -

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...

Read Next
Recommended to you