New Windows malware can also brute-force WordPress websites

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,165
A new malware strain named Clipsa has been making the rounds for the past year, infecting users from all over the world.

What stands out about this new threat is that besides classic malware features -- such as the ability to steal cryptocurrency wallet files, install a cryptocurrency miner, and hijacking the user's clipboard to replace cryptocurrency addresses -- Clipsa also includes a somewhat strange feature that allows it to launch brute-force attacks against WordPress websites.

This behavior is strange, mainly because most brute-force attacks against WordPress sites are carried out by botnets of infected servers or IoT devices.
Seeing desktop malware launch brute-force attacks on WordPress sites isn't novel, but it's strange and extremely rare.

"While we cannot say for sure, we believe the bad actors behind Clipsa steal further data from the breached [WordPress] sites," said Avast malware researcher Jan Rubín, in a technical deep dive into Clipsa's features he published earlier this week.
"We also suspect they use the infected [WordPress] sites as secondary C&C servers to host download links for miners, or to upload and store stolen data," he said.
Read more below:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top