Researchers warn of bulk WordPress and Joomla exploit tool serving fake antivirus malware to users
WordPress and Joomla exploits have existed for years, and cybercriminals have thus been exploiting them for a long time. Yet the situation may have gotten slightly more serious as of late, as there appears to be a bulk exploit tool being used in the wild, targeting sites running both popular content management systems, and having them serve up fake antivirus malware to visitors.
The Sans Institute says it has received reports of multiple exploit attempts on the platforms. The compromised sites are further injected with code which redirects to a third-party sites that in turn serve up the malware.
Fake antivirus threats display a fraudulent scanning result to intimidate users into “purchasing” the fake antivirus program. The Fake AV malware family is being pushed in this case, which features variants for Windows XP, Windows Vista, Windows 7, and even Windows 8.