Tuesday, September 8, 2026

Hacked WordPress Sites Using Visitors’ Browsers For Distributed Brute Force Attacks

Researchers recently uncovered distributed brute force attacks on target WordPress websites using the browsers of innocent site visitors. 

A recent increase in website hacking that targets Web3 and cryptocurrency assets was noticed two weeks ago.

With the use of cryptocurrency drainers, this malware, which spreads among several campaigns, steals assets from compromised wallets and redistributes them.

According to Sucuri researchers, the most notable variation uses the external cachingjs/turboturbo.js script to inject drainers.

The domain name of the turboturbo.js script was modified on February 20, 2024; it was previously dynamiclinks[.]cfd/cachingjs/turboturbo.js, but it is right now dynamiclink[.]lol/cachingjs/turboturbo.js.

“This new wave started on the very same day the new dynamiclink[.]lol domain was registered and hosted on the server with IP 93.123.39.199”, researchers said.

Document
Integrate ANY.RUN in your company for Effective Malware Analysis

Are you from SOC and DFIR teams? – Join With 400,000 independent Researchers

Malware analysis can be fast and simple. Just let us show you the way to:

  • Interact with malware safely
  • Set up virtual machine in Linux and all Windows OS versions
  • Work in a team
  • Get detailed reports with maximum data
  • If you want to test all these features now with completely free access to the sandbox: ..


Distributed Brute Force Attacks On WordPress Sites

Attackers created a second dynamic-linx[.]com domain on February 23, 2024 (which is also hosted on 93.123.39.199 and 94.156.8.251).

By February 25th, researchers were able to identify injections using the dynamic-linx[.]com/chx.js script.

But this new script is very different because it doesn’t load a crypto drainer. Researchers say there is no connection between Web3 and cryptocurrencies and the script’s contents.

The five main stages of this recent attack enable a malicious actor to use websites that have already been infiltrated to undertake distributed brute force attacks against thousands of additional sites that could become targets.

  • Obtain URLs of WordPress sites
  • Extract author usernames
  • Inject malicious scripts
  • Brute force credentials
  • Verify compromised credentials

According to the information shared with Cyber Security News, a task is requested by the user’s browser from the hxxps://dynamic-linx[.]com/getTask.php URL whenever they access an infected webpage. 

When a task is found, the data is processed to extract the URL of the target website, an operational username, and a list of 100 passwords to try.

The visitor’s browser submits the wp.uploadFile XML-RPC API calls to upload a file with the encrypted credentials that were used to authenticate this particular request for each password in the list.

Each task entails 100 API requests! A brief text file containing legitimate credentials is created in the WordPress uploads directory if authentication is successful.

The script notifies the job with a specific taskId and checkId has been finished once all of the passwords have been checked.

At last, the script retrieves the next task and handles an additional set of credentials. And so on, as long as the compromised page is open, without end.

Mitigation

“Most likely, they (attackers) realized that at their scale of infection (~1000 compromised sites) the crypto drainers are not very profitable yet.

Moreover, they draw too much attention and their domains get blocked pretty quickly”, researchers said.

We are reminded by this attack of the importance of creating strong passwords.

You may also want to consider limiting access to the xmlrpc.php file and WordPress admin interface to trusted IP addresses only.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Related Articles

Recent News