In January, my colleague reported about a new Balada Injector campaign found exploiting a recent vulnerability in the widely-used
Popup Builder WordPress plugin which was initially disclosed back in
November, 2023 by Marc Montpas.
In the past three weeks, we’ve started seeing an uptick in attacks from a new malware campaign targeting this same Popup Builder vulnerability. According to PublicWWW, over
3,300 websites have already been infected by this new campaign. Our own SiteCheck
remote malware scanner has detected this malware on over 1,170 sites.
These attacks are orchestrated from domains less than a month old, with registrations dating back to February 12th, 2024:
- ttincoming.traveltraffic[.]cc
- host.cloudsonicwave[.]com