Sucuri Blog Learn about website security, software vulnerabilities, how to protect WordPress, and malware infections from our team of security researchers.
- Backdoors: The Hidden Threat Lurking in Your Websiteby Kyle Knight on January 17, 2025 at 8:56 pm
Website backdoors are a silent yet deadly threat to website security. These stealthy mechanisms bypass standard authentication, providing attackers with persistent, unauthorized access to a website’s backend. Often overlooked, backdoors allow cybercriminals to maintain access long after an initial breach. Understanding the risks they pose and how to mitigate them is essential for website owners who value security, reputation, and operational integrity. The Threat of Website Backdoors Backdoors represent a sophisticated level of intrusion, allowing attackers to maintain control of a system without detection. Continue reading Backdoors: The Hidden Threat Lurking in Your Website at Sucuri Blog.
- Japanese Spam on a Cleaned WordPress Site: The Hidden Sitemap Problemby Puja Srivastava on January 15, 2025 at 11:14 pm
While investigating a compromised WordPress site, we discovered a malware infection causing Japanese spam links to appear in Google search results. Although the site had been cleaned, Google was still crawling and indexing spammy URLs, which impacted the site’s SEO and credibility. Japanese SEO Spam: A Common Threat Japanese SEO spam is a recurring issue that compromises websites to display spammy content in search engine results. Attackers often inject malicious URLs or sitemaps into a site’s infrastructure to manipulate its search rankings. Continue reading Japanese Spam on a Cleaned WordPress Site: The Hidden Sitemap Problem at Sucuri Blog.
- Stealthy Credit Card Skimmer Targets WordPress Checkout Pages via Database Injectionby Puja Srivastava on January 9, 2025 at 9:34 pm
Recently, we released an article where a credit card skimmer was targeting checkout pages on a Magento site. Now we’ve come across sophisticated credit card skimmer malware while investigating a compromised WordPress website. This credit card skimmer malware targeting WordPress websites silently injects malicious JavaScript into database entries to steal sensitive payment details. The malware activates specifically on checkout pages, either by hijacking existing payment fields or injecting a fake credit card form. Where was the malware found? Continue reading Stealthy Credit Card Skimmer Targets WordPress Checkout Pages via Database Injection at Sucuri Blog.
- Vulnerability & Patch Roundup — December 2024by Sucuri Malware Research Team on January 7, 2025 at 11:54 pm
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners about potential threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month. The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected. Continue reading Vulnerability & Patch Roundup — December 2024 at Sucuri Blog.
- Vulnerability & Patch Roundup — November 2024by Sucuri Malware Research Team on December 20, 2024 at 9:09 pm
Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners about potential threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month. The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected. Continue reading Vulnerability & Patch Roundup — November 2024 at Sucuri Blog.
- Malicious Script Injection on WordPress Sitesby Puja Srivastava on December 5, 2024 at 9:48 pm
Recently, our team discovered a JavaScript-based malware affecting WordPress sites, primarily targeting those using the Hello Elementor theme. This type of malware is commonly embedded within legitimate-looking website files to load scripts from an external source. The malware injects a malicious external script into the theme’s header.php file, leading to harmful consequences for site owners and visitors. Domains Involved: spadeanalytica[.]com uph-analytics[. Continue reading Malicious Script Injection on WordPress Sites at Sucuri Blog.
- Credit Card Skimmer Malware Targeting Magento Checkout Pagesby Puja Srivastava on November 27, 2024 at 12:21 am
Magento websites are a frequent target for cybercriminals due to their widespread usage in eCommerce and the valuable customer data they handle. During a routine investigation, we discovered a malicious JavaScript injection targeting Magento websites. This malware dynamically creates a fake credit card form or extracts payment fields directly depending on the variant of the malware, activating only on checkout pages. The stolen data is then encrypted and exfiltrated to a remote server. Overview of the infection: Initially discovered by Weston Henry, a colleague on our team, the malware is designed to target Magento-powered eCommerce websites, specifically their checkout processes. Continue reading Credit Card Skimmer Malware Targeting Magento Checkout Pages at Sucuri Blog.
- Simple Include Statement Hides Casino Spamby Kayleigh Martin on November 14, 2024 at 10:35 pm
Just as there are countless types of websites on the internet, there are just as many attackers seeking to exploit them. These attackers develop malicious code that continuously evolves, constantly finding new ways to harm their next target. Sometimes, threat actors rely on heavy obfuscation to conceal their malicious code, while others use stealthier methods to disguise malware that is in plain sight. We recently stumbled upon a WordPress infection where the victim’s website was hosting a spam doorway that included casino and slot links based out of Indonesia. Continue reading Simple Include Statement Hides Casino Spam at Sucuri Blog.
- PHP Reinfector and Backdoor Malware Target WordPress Sitesby Puja Srivastava on November 13, 2024 at 9:55 pm
We recently observed a surge in WordPress websites being infected by a sophisticated PHP reinfector and backdoor malware. While we initially believed that the infection was linked to the wpcode plugin, we found that several sites without this plugin were compromised as well. Upon deeper investigation, we discovered that this malware not only reinfects website files but also embeds malicious code into other plugins and database tables wp_posts and wp_options. One backdoor we uncovered revealed how attackers maintain unauthorized access to these sites, further spreading the infection. Continue reading PHP Reinfector and Backdoor Malware Target WordPress Sites at Sucuri Blog.
- Malware Steals Account Credentialsby Matt Morrow on November 8, 2024 at 9:22 pm
It’s common for malware to target e-commerce sites, and these attackers are usually seeking to steal credit card details. In most cases, they will insert scripts that extract data from the checkout forms to siphon fields like the cardholder name, card number and expiration date. Once they have that information, their job is done and they’ll use the data for other nefarious purposes (usually putting it up for sale on the black market). However, every now and then we encounter a case where in addition to that they are also looking to steal details for accounts that customers have created on these sites along with admin account credentials. Continue reading Malware Steals Account Credentials at Sucuri Blog.
- 2024 Credit Card Theft Season Arrivesby Ben Martin on November 7, 2024 at 8:12 pm
The holiday shopping season is just around the corner, and it’s the time of year the eCommerce website owners need to be most on their guard. Credit card stealing malware, commonly referred to as “MageCart”, is most rampant during the holiday shopping season. Attackers are always aiming to maximize their profits. As such, they know that if they focus their time and efforts at the last quarter of the year they’ll have more stolen card details to sell on the dark web when the time comes to cash in on their ill-gotten gains. Continue reading 2024 Credit Card Theft Season Arrives at Sucuri Blog.