Written by 10:00 am Happenings, News โ€ข Views: 120

๐Ÿšจ Hackers Exploit WordPress Sites to Spread Infostealing Malware on Windows & Mac

Hackers are targeting outdated WordPress sites to distribute malware on Windows & Mac, stealing passwords and sensitive data. Stay protected!

โš ๏ธ WordPress Websites Under Attack: Malware Campaign in Full Swing

๐Ÿ”ด Cybersecurity experts warn that thousands of WordPress websites have been compromised in a massive hacking campaign, tricking users into installing password-stealing malware on Windows and macOS devices.

๐Ÿšจ The attack relies on outdated WordPress versions and vulnerable plugins, affecting some of the most-visited sites on the internet.

๐Ÿ”Ž Key Takeaways:
โœ… Hackers display fake Chrome update pages to lure victims.
โœ… Malware variants include Amos (macOS) & SocGholish (Windows).
โœ… Over 10,000 hacked WordPress sites involved in the campaign.
โœ… Sensitive data stolen: passwords, session cookies, crypto wallets, and more.

๐Ÿ“ข Security firm c/side CEO Simon Wijckmans confirmed that the hacking campaign is active and widespread.


๐Ÿ›‘ How Does the Attack Work?

๐Ÿ” Researchers discovered that infected WordPress sites automatically redirect visitors to a fraudulent Chrome update page.

1๏ธโƒฃ User visits a hacked WordPress site.
2๏ธโƒฃ The site instantly loads a fake Chrome update prompt.
3๏ธโƒฃ Clicking โ€œUpdateโ€ downloads malicious software tailored for either Windows or macOS.
4๏ธโƒฃ The malware steals credentials, session cookies, crypto wallets, and sensitive data.

๐Ÿ’ป Windows Users โ†’ SocGholish malware infects systems.
๐Ÿ Mac Users โ†’ Amos (Atomic Stealer) malware steals data.


๐Ÿ”Ž Amos & SocGholish: What You Need to Know

Amos (Atomic Stealer) – macOS Malware

๐Ÿšจ Discovered by SentinelOne in 2023, Amos is a powerful password-stealing malware:
โœ” Targets macOS users.
โœ” Extracts login credentials, cookies, & crypto wallets.
โœ” Distributed via Telegram as malware-as-a-service (MaaS).

๐Ÿ”Š Cybersecurity expert Patrick Wardle warns that Amos is the most prolific Mac infostealer but requires manual installation by the user.

SocGholish – Windows Malware

๐Ÿ’€ Windows users face SocGholish, a malware that:
โœ” Deploys fake software updates.
โœ” Compromises corporate networks.
โœ” Installs remote access trojans (RATs).

๐Ÿ•ต๏ธโ€โ™‚๏ธ Hackers use this stolen data for large-scale credential theft & financial fraud.


๐Ÿš€ How to Stay Safe & Protect Your Devices

๐Ÿ” Cybersecurity Best Practices:
โœ… Update WordPress & plugins to the latest versions.
โœ… Only install software from official sources (Google Chrome, Apple App Store, Microsoft Store).
โœ… Enable two-factor authentication (2FA) on all accounts.
โœ… Use a trusted antivirus solution & enable real-time protection.
โœ… Scan websites before clicking links (use tools like Google Safe Browsing).

๐Ÿš€ Pro Tip: Always update Google Chrome via its built-in update feature, NOT from pop-ups or website prompts!


๐Ÿ“ข Final Thoughts: A Growing Cybersecurity Threat

Cybercriminals are constantly evolving their tactics to exploit vulnerabilities in popular platforms like WordPress. If your website runs on WordPress, itโ€™s critical to update it regularly to avoid becoming an entry point for hackers.

โš ๏ธ If you see a pop-up asking you to update Chromeโ€”DONโ€™T CLICK IT! Instead, navigate to chrome://settings/help in your browser and update it manually.

๐Ÿ›ก Stay safe, stay updated, and share this article to spread awareness! ๐Ÿ’ป๐Ÿš€

Visited 120 times, 1 visit(s) today
Close