Close Menu
NotesleuNotesleu
    Facebook X (Twitter) Instagram
    Tuesday, February 10
    Facebook X (Twitter) Instagram
    NotesleuNotesleu
    • Home
    • General News
    • Cyber Attacks
    • Threats
    • Vulnerabilities
    • Cybersecurity
    • Contact Us
    • More
    NotesleuNotesleu
    Home»Cybersecurity»Massive Balada Injector Attacks Continue to Plague WordPress Sites Worldwide
    Cybersecurity

    Massive Balada Injector Attacks Continue to Plague WordPress Sites Worldwide

    By securnerd2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Follow Us
    Google News

    In a concerning surge of cyber threats, over 17,000 WordPress websites fell victim to the relentless onslaught of Balada Injector attacks last month. Exploiting vulnerabilities in premium theme plugins, multiple Balada Injector campaigns wreaked havoc by compromising and infecting these sites.

    First identified in December 2022 by cybersecurity firm Dr. Web, the Balada Injector operation involves the use of various exploits targeting well-known flaws in WordPress plugins and themes. This malicious endeavor installs a Linux backdoor, redirecting visitors to compromised websites to fraudulent tech support pages, fake lottery winnings, and push notification scams. Whether part of larger scam campaigns or sold as a service to cybercriminals, this infiltration represents a significant threat to online security.

    Sucuri, a renowned cybersecurity company, revealed that Balada Injector has been active since 2017, estimating that it has infiltrated nearly one million WordPress sites. The recent wave of attacks has specifically targeted the CVE-2023-3169 cross-site scripting (XSS) flaw in tagDiv Composer, a companion tool for tagDiv’s Newspaper and Newsmag themes widely used by thriving online platforms. With an attack surface encompassing 155,500 websites, the assault began in mid-September, immediately following the disclosure of vulnerability details and the release of a proof-of-concept exploit.

    This campaign witnessed sophisticated tactics, including the use of malicious plugins like wp-zexit.php, enabling threat actors to remotely send PHP code, redirecting users to scam sites under their control. Despite efforts by tagDiv to address the flaw by recommending theme updates and security plugins, thousands of sites have already been compromised. Sucuri identified six distinct attack waves, characterized by varying techniques and domains, indicating the adaptability and agility of the threat actors.

    Sucuri’s report provides critical insights into these attacks, emphasizing the importance of upgrading the tagDiv Composer plugin to version 4.2 or later to mitigate the vulnerability. Website owners are urged to maintain updated themes and plugins, remove dormant user accounts, and conduct regular scans for hidden backdoors. Sucuri offers a free scanner designed to detect most Balada Injector variants, providing an essential tool for WordPress users to safeguard their websites against this pervasive threat. As the cyber landscape evolves, vigilance and proactive security measures remain paramount in defending against these relentless attacks.

    Found this news interesting? Follow us on Twitter  and Telegram to read more exclusive content we post.

    Post Views: 62

    Related Posts

    • Checkout
    • Homepage
    • Complete HTML Handwritten Notes
    • Why Do Restaurant Burgers Taste Better?
    Follow on Google News
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Add A Comment
    Leave A Reply Cancel Reply

    Recent Post

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024

    Top 7 Open-Source LLMs for 2024 and Their Uses

    July 18, 2024
    About Us
    About Us

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Latest

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024
    Popular Post

    Microsoft Enhances Windows 11 Security with Kerberos Authentication Over NTLM Protocol

    October 15, 202318 Views

    New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide

    December 21, 202337 Views

    Malicious Ads Exploit macOS Users, Unleashing Stealer Malware

    April 1, 202418 Views
    • Contact Us
    • About US
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 Notesleu. Designed by NIM.

    Type above and press Enter to search. Press Esc to cancel.