By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    Morris Worm Turns 25
    12 months ago
    Meet the iPhone malware that tracks your every move
    12 months ago
    Virus can inflict physical harm onto a PC: myth or truth?
    12 months ago
    Latest News
    Two privilege escalation vulnerability in Simple Membership Plugin
    12 hours ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (September 11, 2023 to September 17, 2023)
    7 days ago
    Exploring Winrar Vulnerability (CVE-2023-38831) | McAfee Blog
    1 week ago
    Two PHP Object Injection Vulnerabilities Fixed in Essential Blocks
    1 week ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    Why none of the Windows 8 upgrade guides you find will help
    12 months ago
    Windows 11 build 25188 outs with touch keyboard updates
    12 months ago
    How to upgrade from Windows 10 to Windows 11
    12 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    7 months ago
    Now you can speed up any video in your browser
    7 months ago
    How to restore access to a file after EFS or view it on another computer?
    8 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    8 months ago
  • How To
    How ToShow More
    How to get the latest Windows 11 innovations
    15 hours ago
    Dynamic Lighting is now available on Windows 11
    15 hours ago
    Writing poems using LLama 2 on Workers AI
    Writing poems using LLama 2 on Workers AI
    15 hours ago
    serverless GPU-powered inference on Cloudflare’s global network
    serverless GPU-powered inference on Cloudflare’s global network
    15 hours ago
    You can now use WebGPU in Cloudflare Workers
    You can now use WebGPU in Cloudflare Workers
    15 hours ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to empty the Recycle Bin on a schedule on Windows 10?
    11 months ago
    Passing through obstacles in a game with a dinosaur in Google Chrome
    11 months ago
    How to restore VKontakte correspondence?
    11 months ago
    Latest News
    How to install September 2023 update with 23H2 features for Windows 11
    20 hours ago
    How to uninstall September update (KB5030310) from Windows 11
    20 hours ago
    How to remove the quiet mode icon in the corner of the iPhone 15 screen ProiPhone 15 Pro and iPhone
    2 days ago
    Sberbank has figured out how to effectively catch scammers – it will listen to everything you
    2 days ago
  • Glossary
  • My Bookmarks
Reading: Sodinokibi ransomware spreads by creating fake forums on hacked websites
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
ThreatsWordpress Threats

Sodinokibi ransomware spreads by creating fake forums on hacked websites

Tom Grant
Last updated: 13 October
Tom Grant 2 years ago
Share
3 Min Read

BleepingComputer Founder Lawrence Abrams warned that Sodinokibi ransomware operators are using a very sophisticated method to distribute their malware. So, they create fake Q&A forums on hacked WordPress sites, and then post fake messages there, disguised as admin responses and containing links to download malware.

In fact, the criminals use a fake overlay that places a forum with questions and answers on top of the content of the hacked site. As a result, the fake forum post contains information that is actually about the content of the page the user is visiting. This gives the impression that the answer and link posted by the “admin” are legitimate.

Abrams writes that the new Sodinokibi distribution method was first noticed by an information security expert known by the pseudonym Aura. The actions of the attackers are similar to the old attack technique HoeflerText. The essence of this technique is reflected in its name: the user is shown a pop-up message and is offered to download the HoeflerText font package. Allegedly, without this, it is impossible to view the landing page. In the case of Sodinokibi, the attackers also inject JavaScript into HTML on hacked sites, as shown in the illustration below. Moreover, the embedded URL will be active for all visitors, but contains data only if the user visits the site for the first time or has not visited the resource for a certain period of time.

So, if the victim came to the site for the first time, the script will cause the appearance of a fake a message in French that will be displayed over the content of the site. Moreover, if the user refreshes the page again, the script will not be run, and only the normal page will be displayed. A video demonstrating the attack can be seen below.

The specialist warns that to protect against such attacks, you should take care to use security software, and also never execute files that end in the .js extension.


Translate this article

TAGGED: Chrome, Firefox, Malware, RC4, Security, Software, WordPress
Tom Grant October 13, 2022 October 31, 2021
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Two privilege escalation vulnerability in Simple Membership Plugin
Two privilege escalation vulnerability in Simple Membership Plugin
Wordpress Threats 15 hours ago
How to get the latest Windows 11 innovations
Windows 15 hours ago
Dynamic Lighting is now available on Windows 11
Windows 15 hours ago
Writing poems using LLama 2 on Workers AI
Writing poems using LLama 2 on Workers AI
Apps 15 hours ago
serverless GPU-powered inference on Cloudflare’s global network
serverless GPU-powered inference on Cloudflare’s global network
Apps 15 hours ago

You Might Also Like

Two privilege escalation vulnerability in Simple Membership Plugin
Wordpress Threats

Two privilege escalation vulnerability in Simple Membership Plugin

15 hours ago
Windows

How to get the latest Windows 11 innovations

15 hours ago
Writing poems using LLama 2 on Workers AI
Apps

Writing poems using LLama 2 on Workers AI

15 hours ago
serverless GPU-powered inference on Cloudflare’s global network
Apps

serverless GPU-powered inference on Cloudflare’s global network

15 hours ago
Show More

Related stories

How to upgrade to Windows 11 23H2 with Installation Assistant
Critical Vulnerability in Forminator Plugin
How to blur image background in Photos for Windows 11
How to download official Windows 11 23H2 ISO file
PHP Object Injection Vulnerability in Flatsome Theme
How to download Windows 11 22H2 ISO after 23H2 releases
Previous Next

10 New Stories

You can now use WebGPU in Cloudflare Workers
How to install September 2023 update with 23H2 features for Windows 11
How to uninstall September update (KB5030310) from Windows 11
Traffic anomalies and notifications with Cloudflare Radar
Sippy helps you avoid egress fees while incrementally migrating data from S3 to R2
the modern way to connect and protect your clouds, networks, applications and users
Previous Next
Hot News
Two privilege escalation vulnerability in Simple Membership Plugin
How to get the latest Windows 11 innovations
Dynamic Lighting is now available on Windows 11
Writing poems using LLama 2 on Workers AI
serverless GPU-powered inference on Cloudflare’s global network
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?