Hackers are increasingly hijacking legitimate — but often neglected — WordPress sites and turning them into covert phishing traps, a Monday analysis from Kaspersky researchers revealed.
By secretly inserting their own malicious pages onto abandoned, forgotten, or just poorly-maintained sites, phishing operators are able to set up lures to swipe user inputs. The most common sites being impersonated are European Banks, popular delivery services, and even Netflix.
The sensitive data captured by these fraudulent pages, like “credentials for a website, bank card details including the CVV or other personal information,” gets stored within the website’s control panel, Kaspersky explained.
When compromised, this data either can be sold on the dark web or used further to access the victim’s bank or other accounts.
Staggering Number of Compromised WordPress Sites
Hackers tend to go after smaller websites that have been neglected, or whose owners don’t have the resources or ability to recognize their presence right away.
From mid-May to July 31, 2023, Kaspersky found 22,400 different WordPress websites that had been hacked and turned into phishing bait. During this time frame, users made more than 200,000 visits to compromised sites, researchers added.
“Abandoned websites end up captured by cybercriminals fairly often. A lack of maintenance and security patches means they are easy to compromise using a known exploit,” Kaspersky said.
“Besides, on a long-neglected site, phishing pages can stay up for long periods of time, as no one monitors what gets published, which is exactly what scammers look for.”
Targeted Entities and How to Recognize Compromised Sites
The most commonly imitated business entities include Netflix, European banks, and popular delivery services, according to Kaspersky — the hackers’ ploy to win trust and ensnare victims into a trap.
For regular users, being aware of the telltale signs of a compromised site is the first line of defense. Simply put, if you’re visiting Netflix, the URL should read: https://www.netflix.com.
For phishing domains, subtle indicators like the webpage URL containing names like “/wp-Config/, /wp-content/, /wp-admin/, /wp-includes/ or similar, and the destination directory contains a PHP file” should be warning signs, researchers warned.
Kaspersky displayed a screenshot of such a Netflix phishing page — the telltale sign there was the URL of the page in the browser had nothing to do with Netflix itself and included: “wp-admin/js/js/js/..” in the address bar.
Hackers Compromise Unpatched Sites in Two Ways
First, Kaspersky explained that hackers may exploit security vulnerabilities, especially prevalent in platforms like WordPress. Second, they may hijack administrator accounts, either by brute-forcing weak passwords or using leaked credentials — available on the dark web or on hacker Telegram channels.
Kaspersky pointed out that these crafted pages are sometimes impossible to distinguish from a legitimate one: “… every section is where it is supposed to be, and only relevant information can be seen,” researchers said.
Similarly, hackers have been known to target PayPal and Facebook users with such tactics i.e. involving spoofed pages.
Given that WordPress is a leading global website-building service, with statistics showing “43.1% of all websites on the internet are powered by the WordPress content management system [CMS],” its vulnerabilities become attractive for cybercriminals, the analysis noted.
Perhaps most key of all is that there is “a huge number of third-party plugins designed for extending the functionality of this popular platform [WordPress]. New vulnerabilities exploited by hackers are discovered both in plugins and in WordPress itself on a regular basis,” the analysis added.
Protecting Your Websites and Yourself
For website administrators, employing solid security practices such as unique passwords, multi-factor authentication, and regular server software updates is essential to avoid these traps, Kaspersky said. Also, since the core vulnerabilities often stem from third-party plugins, they must be scrutinized and deactivated if not necessary.
“… most hacked websites have broken links to other sections on the home page, as hackers delete the original directories, replacing these with phishing content,” the analysis noted.
Kaspersky stresses the importance of regular cyber training sessions to educate both website admins and the general public. In a risky digital landscape, maintaining updated knowledge and using top-shelf cybersecurity tools will always be the key to staying ahead of the threats.
As such, VPNOverview recommends you employ a strong, real-time antivirus solution across all of your devices that can detect suspicious webpages and block dangerous internet traffic.
Check out our top antivirus picks with a built-in VPN, which have the added benefit of having a VPN included to encrypt your internet traffic. Also, ensure you use bulletproof passwords across all accounts, ideally coupled with a factor of authentication at the very least.
For more phishing-related news, follow us on Twitter, Threads, and Mastodon!
