"Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks"
"Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks"
Threat actors are using malicious JavaScript injections to launch brute-force attacks on WordPress sites. According to Sucuri security researcher Denis Sinegubko, the distributed brute-force attacks target WordPress websites via the browsers of site visitors. The activity is part of an attack wave in which compromised WordPress sites are used to directly inject cryptocurrency drainers such as Angel Drainer or redirect site visitors to Web3 phishing sites with drainer malware.