By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    What is an Exploit? -Kaspersky Daily
    8 months ago
    Darkhotel APT in luxury Asian hotels
    8 months ago
    Kaspersky Lab expert Andrey Pozhogin answers questions about ransomware
    8 months ago
    Latest News
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
    3 days ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    4 days ago
    W3 Eden Addresses Authenticated Stored XSS Vulnerability in Download Manager WordPress Plugin
    6 days ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 8, 2023 to May 14, 2023)
    1 week ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    Keylogger found on 5500 sites running WordPress
    Keylogger found on 5500 sites running WordPress
    8 months ago
    Windows 11 build 22622.575 (KB5016694) releases in the Beta Channel
    8 months ago
    How to create restore point on Windows 11
    8 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    3 months ago
    Now you can speed up any video in your browser
    3 months ago
    How to restore access to a file after EFS or view it on another computer?
    4 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    4 months ago
  • How To
    How ToShow More
    Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
    1 day ago
    NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
    1 day ago
    How Oxy uses hooks for maximum extensibility
    How Oxy uses hooks for maximum extensibility
    2 days ago
    The personal threat landscape: securing yourself smartly
    2 days ago
    Announcing new Windows 11 innovation, with features for secure, efficient IT management and intuitive user experience
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to create local account on Windows 10
    4 months ago
    How to enable Nearby Sharing on Windows 11
    3 months ago
    How to enable Previous Versions to recover files on Windows 11
    3 months ago
    Latest News
    How to enable new header UI for File Explorer on Windows 11
    4 days ago
    How to enable free VPN on Microsoft Edge
    6 days ago
    How to use Ventoy to create bootable USB of Windows 11, 10
    6 days ago
    How to fix internal drive detected as removable storage bug on Windows 11
    7 days ago
  • Glossary
  • My Bookmarks
Reading: Sodinokibi ransomware spreads by creating fake forums on hacked websites
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
ThreatsWordpress Threats

Sodinokibi ransomware spreads by creating fake forums on hacked websites

Tom Grant
Last updated: 13 October
Tom Grant 2 years ago
Share
3 Min Read

BleepingComputer Founder Lawrence Abrams warned that Sodinokibi ransomware operators are using a very sophisticated method to distribute their malware. So, they create fake Q&A forums on hacked WordPress sites, and then post fake messages there, disguised as admin responses and containing links to download malware.

In fact, the criminals use a fake overlay that places a forum with questions and answers on top of the content of the hacked site. As a result, the fake forum post contains information that is actually about the content of the page the user is visiting. This gives the impression that the answer and link posted by the “admin” are legitimate.

Abrams writes that the new Sodinokibi distribution method was first noticed by an information security expert known by the pseudonym Aura. The actions of the attackers are similar to the old attack technique HoeflerText. The essence of this technique is reflected in its name: the user is shown a pop-up message and is offered to download the HoeflerText font package. Allegedly, without this, it is impossible to view the landing page. In the case of Sodinokibi, the attackers also inject JavaScript into HTML on hacked sites, as shown in the illustration below. Moreover, the embedded URL will be active for all visitors, but contains data only if the user visits the site for the first time or has not visited the resource for a certain period of time.

So, if the victim came to the site for the first time, the script will cause the appearance of a fake a message in French that will be displayed over the content of the site. Moreover, if the user refreshes the page again, the script will not be run, and only the normal page will be displayed. A video demonstrating the attack can be seen below.

The specialist warns that to protect against such attacks, you should take care to use security software, and also never execute files that end in the .js extension.


Translate this article

TAGGED: Chrome, Firefox, Malware, RC4, Security, Software, WordPress
Tom Grant October 13, 2022 October 31, 2021
Share this Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
Windows 1 day ago
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
Windows 1 day ago
How Oxy uses hooks for maximum extensibility
How Oxy uses hooks for maximum extensibility
Apps 2 days ago
The personal threat landscape: securing yourself smartly
How To 2 days ago
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Wordpress Threats 3 days ago

Recent Posts

  • Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
  • NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
  • How Oxy uses hooks for maximum extensibility
  • The personal threat landscape: securing yourself smartly
  • Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)

You Might Also Like

Windows

Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16

1 day ago
How Oxy uses hooks for maximum extensibility
Apps

How Oxy uses hooks for maximum extensibility

2 days ago
How To

The personal threat landscape: securing yourself smartly

2 days ago
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Wordpress Threats

Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)

3 days ago
Show More

Related stories

How to Use Cloudflare to Secure Your WordPress Site
How To Starting Chrome from the command line
How to fix error 0x80070057 in Chrome?
Windows 10 How To Disable Slide to Shutdown
Windows search not working (FIX)
How to watch movies and TV series for free on Kinopoisk?
Previous Next

10 New Stories

How to enable new header UI for File Explorer on Windows 11
Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
Announcing new Windows 11 innovation, with features for secure, efficient IT management and intuitive user experience
How to enable free VPN on Microsoft Edge
How to use Ventoy to create bootable USB of Windows 11, 10
Announcing Cohort #2 of the Workers Launchpad
Previous Next
Hot News
Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
How Oxy uses hooks for maximum extensibility
The personal threat landscape: securing yourself smartly
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
10alert.com10alert.com
Follow US

© 10 Alert Network. All Rights Reserved.

  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?