Sporty Hub
  • Home
  • Sports
    • Football
    • Basketball
    • Boxing
    • Racing
    • Tennis
    • Volleyball
  • Technology
  • Video Games
  • Consoles and Gaming Hardware
No Result
View All Result
Sporty Hub
  • Home
  • Sports
    • Football
    • Basketball
    • Boxing
    • Racing
    • Tennis
    • Volleyball
  • Technology
  • Video Games
  • Consoles and Gaming Hardware
No Result
View All Result
Sporty Hub
No Result
View All Result

Over 15,000 WordPress Sites Affected in Malicious SEO Campaign

sportyhub by sportyhub
November 15, 2022
in Technology
0
black and white wordpress graphic
0
VIEWS
Share on FacebookShare on Twitter


More than 15,000 WordPress websites have been compromised and redirected to fake portals to increase spam website traffic.

black and white wordpress graphic

A new malicious SEO campaign has successfully compromised over 15,000 WordPress websites. The aim of the campaign is to redirect users to fake Q&A sites to increase visitor traffic.

Over 15,000 WordPress sites compromised

In a new black hat redirect campaign, hackers managed to compromise over 15,000 WordPress websites to boost the search engine rankings of various bogus websites.

As reported in a Sucuri blog post, there has been a noticeable increase in WordPress malware redirect sites since September 2022. These redirect sites lead users to low-quality fake Q&A portals. In the months of September and October alone, hackers were able to successfully target over 2,500 sites.

Sucuri, a security researcher, has so far detected 14 bogus websites with their servers masked by a proxy. The questions displayed on the sites are pulled from other legitimate question and answer platforms. With increased SEO ranking, these sites can reach more people.

Fake Q&A sites can spread malware

person touching matrix code

Fake sites used in this redirect campaign are capable of spreading malware to visitors. Unlike many malicious sites, these particular fake Q&A forums are capable of modifying more than 100 infected files per site. This is not often done, as it makes their detection and removal more likely.

In the aforementioned blog post, Sucuri stated that most of the infected files are basic WordPress files, but also listed a number of the most commonly infected files, all of which have .php extensions. The list of infected .php files is shown below:

  • ./wp-signup.php
  • ./wp-cron.php
  • ./wp-links-opml.php
  • ./wp-settings.php
  • ./wp-comments-post.php
  • ./wp-mail.php
  • ./xmlrpc.php
  • ./wp-activate.php
  • ./wp-trackback.php
  • ./wp-blog-header.php

Sucuri also pointed out that the malware was found to be present in some pseudo-legitimate filenames dropped by the hackers themselves, including:

  • RVbCGlEjx6H.php
  • lfojmd.php
  • wp-newslet.php
  • wp-ver.php
  • wp-logln.php

Hackers breach method can be vulnerable plugin or brute force

Sucuri has yet to uncover how these black hat hackers breach these WordPress sites, but a vulnerable plugin or brute force attack is thought to be the most likely culprits. Hackers can use an exploit kit to scan plugins for security vulnerabilities to highlight a target. Alternatively, the WordPress site admin login password could be cracked using an algorithm in a brute force attack.

WordPress sites are common targets of exploitation

This is by no means the first time that WordPress sites have been targeted by malicious actors. Millions of WordPress sites have been compromised by cybercriminals in the past, and no doubt many more will continue to fall victim to such attacks.

Previous Post

Fight Talk: Natasha Jonas proves good things come to good people

Next Post

Small Hall Spotlight: Owen Gidman on making your pro boxing debut away from the big lights

Next Post
Small Hall Spotlight: Owen Gidman on making your pro boxing debut away from the big lights

Small Hall Spotlight: Owen Gidman on making your pro boxing debut away from the big lights

Popular News

  • Google Pixel 6a front and back view

    The Pixel 6a and Pixel 7 Pro Have the Best Smartphone Cameras of 2022, According to Blind Test

    0 shares
    Share 0 Tweet 0
  • Discord voice chat rolls out to all Xbox users

    0 shares
    Share 0 Tweet 0
  • Aberdeen 0-1 Celtic: Callum McGregor scores late winner for champions

    0 shares
    Share 0 Tweet 0
  • FA Cup third round: Cardiff City 2-2 Leeds United – visitors fight back to draw

    0 shares
    Share 0 Tweet 0
  • HBO’s The Last of Us: Every type of infected zombie

    0 shares
    Share 0 Tweet 0

Sporty Hub

Welcome to Sporty Hub. Get the latest news about everything related to sports and to video games diretly from our website. We select only the best news around the world for your entertainment and to keep you updated on all the latest sports and video games news in one place.

Categories

  • American Football
  • Basketball
  • Boxing
  • Consoles and Gaming Hardware
  • Cricket
  • Football
  • Golf
  • Racing
  • Sports
  • Technology
  • Tennis
  • Video Games
  • Volleyball

Recent Posts

  • New Zealand v England: Coach Brendon McCullum ‘in awe’ of his players
  • When and where to watch the Puppy Bowl 2023
  • Thursday’s transfer gossip: Branthwaite, Aubameyang, Silva, Bellingham, Foster, De Jong
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2022 Sportyhub.live | All Rights Reserved.

No Result
View All Result
  • Home
  • Sports
    • Football
    • Basketball
    • Boxing
    • Racing
    • Tennis
    • Volleyball
  • Technology
  • Video Games
  • Consoles and Gaming Hardware

Copyright © 2022 Sportyhub.live | All Rights Reserved.