GoDaddy Engineering
Read post

Threat Actors Push ClickFix Fake Browser Updates Using Stolen Credentials

GoDaddy Security Researchers have identified a surge in malware distribution through fake WordPress plugins. These plugins appear legitimate but inject JavaScript for fake browser update prompts, leveraging social engineering to compromise users. Threat actors use stolen admin credentials to install these plugins on websites, rather than exploiting WordPress vulnerabilities. The malware employs blockchain technology and smart contracts to deliver payloads. Over 25,000 sites have been detected with this variant since August 2023, with over 6,000 affected since June 2024. The threat continues to evolve, using multiple vectors and automated processes to evade detection.

    #security#webdev#javascript#wordpress#malware
Oct 17, 2024•13m read time•From godaddy.com
Post cover image
Table of contents
Key findingsOverviewFake WordPress pluginsPlugin codeMalicious scriptsPrevious iteration of fake ClickFix plugins - June 2024Payloads hosted in Github and BitBucketAttack log analysis - September 2024Stolen credentials distribute fake browser updatesIndicators of compromise
11 Impressions
GoDaddy Engineering's image
GoDaddy Engineering

GoDaddy's resource offers insights, tutorials, and resources for website owners, entrepreneurs, and ...

6 Followers

•

15 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard