Cybercriminals have stopped buying their own command servers and moved to a cheaper and less conspicuous infrastructure: they take over abandoned web resources running outdated versions of content management systems and obsolete plugins. This is reported by RBC-Ukraine, citing a report by cybersecurity experts at Check Point Research. According to the researchers, some of the infected resources had up to 40 unpatched vulnerabilities, which made such sites an ideal quiet staging ground for attacks.
How the attack scheme works
The attackers embedded malicious code into the compromised sites that showed visitors a fake CAPTCHA verification window using the popular ClickFix social engineering scheme. Users were convinced that they were not a robot and were asked to copy and run a command line in the PowerShell console for verification. It was precisely this step that triggered the chain of malware downloads onto the victim's computer, bypassing some of the standard protective mechanisms.
What was loaded onto the victims' computers
After the command was executed, a whole set of viruses was installed on the PC: from the SilentEncryptor ransomware and network worms to the SilentDataCollector spyware module. The broken WordPress sites were used repeatedly — for storing stolen data, dumping logs, and as command servers controlling the botnet.
How the investigation became possible
According to the report, the botnet was uncovered due to gross operational security (OPSEC) mistakes by the creators of the infrastructure themselves. In particular, one of the operators of the hacker group accidentally infected their own work computer with the spyware module. As a result, the virus automatically collected and uploaded data to the developers' server, including information about other victims, which gave researchers the key to exposing the entire scheme.
Why WordPress is the main target
The WordPress platform accounts for about 43 percent of the entire global website market, which makes it a priority target for such attacks. A significant portion of resources is eventually abandoned by their owners but remains online with old versions of the core and plugins that no longer receive security updates.
Recommendations for website owners and users
Experts advise website owners to immediately update the WordPress engine itself, as well as all installed plugins and themes, or to remove those that are no longer supported by their developers. It is important for ordinary users to remember a simple rule: no CAPTCHA verification ever requires copying commands and running them in the Windows or PowerShell console. You should immediately leave such sites and not perform the proposed actions.