Stealthy Malware Disguises Itself as a WordPress License Key
#1
Quote:A spam-injecting malware is targeting WordPress site owners by disguising itself as a legitimate license key for a WordPress design theme.

According to analysis from Sucuri, a customer opened a malware removal ticket reporting “some weird spam URLs injected onto their WordPress website.” After further investigation into the files on the website, analysts uncovered a hidden encoded spam injector malware in the “./wp-content/themes/toolbox/functions.php” WordPress theme, masquerading as a license key.
WordPress themes are essentially website templates, specifying the fonts, colors, image placement and other design elements for a site. They can also be customized with tailored elements.

When a customer orders a theme, it comes with a license key, like any software would. This key is required for any future updates, features and security patches.

“A license key is a place where a webmaster might not expect to find an infection,” said Moe Obaid, security analyst at Sucuri, in a Wednesday post. “The attacker formatted the encoded injector to look like a theme’s license key in order to distract the eyes of a less-trained security analyst from suspecting this to be malicious code.”

Source: https://threatpost.com/malware-wordpress...ey/141315/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Stealthy Malware Disguises Itself as a WordPress License Key - by silversurfer - 30 January 19, 18:30

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.18  Added op...Kool — 08:37
Mozilla Firefox Browser 149.0
Mozilla Firefox Br...harlan4096 — 08:09
AxCrypt 3.0.0.82
AxCrypt 3.0.0.82: ...harlan4096 — 08:07
uBOLite 2026.323.2044 (already available...
uBOLite 2026.323.2...harlan4096 — 08:06
AnyDesk 9.6.12 for Windows
Version 9.6.12 for...harlan4096 — 08:05

[-]
Birthdays
Today's Birthdays
avatar (43)artmaGoork
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>