Countless WordPress Websites Compromised to Display Phony reCAPTCHA and Capture Windows Passwords

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Alert on Compromised WordPress Sites Used in Malware Campaign

Numerous WordPress websites have been infiltrated and are currently serving as vehicles for an elaborate malware distribution scheme.

This campaign employs a combination of browser persistence mechanisms, blockchain-based payloads, fraudulent reCAPTCHA prompts, and fileless execution techniques to deploy the Amatera information stealer across Windows platforms.

What distinguishes this operation is its elaborate nine-layer structure designed to leave minimal digital forensic traces.

With no standard payload server in sight and only a scant number of useful files to analyze, the malware utilizes a browser-resident persistence strategy that can survive site-level remediation efforts.

The infiltration initiates with a malicious plugin that injects a script named front-probe.js, while simultaneously registering a Service Worker termed nochain-sw.js.

Service Workers, which are browser elements intended to facilitate offline capabilities and manage requests, are weaponized in this particular instance.

This insidious code intercepts HTML responses, strips away Content-Security-Policy headers, and injects JavaScript under the control of the attackers into the pages accessed by unsuspecting users.

It activates immediately using the commands skipWaiting() and clients.claim(), which allows it to commandeer browsing sessions without the need to wait for a new session to commence.

Remarkably, the Service Worker is engineered to evade detection by WordPress administrators. It strategically ignores requests linked to /wp-admin, /wp-login.php, the wordpress_logged_in cookie, or a manipulated nc_skip=1 cookie owned by the operator.

This careful filtration ensures that ordinary users—who remain logged out—are subjected to the fraudulent verification prompt, while the site proprietor, who is most capable of recognizing the compromise, remains in the dark.

The injected JavaScript connects to the Base blockchain, probing smart contract 0x58460d0b3d4d6b03761c89120393c0c676676496.

In a departure from conventional tactics, the operator secures the next stage code not directly on the compromised website or through ephemeral servers, but embeds the payload data within contract information, retrieving it through read-only RPC calls.

This method, dubbed EtherHiding, empowers cybercriminals to modify downstream instructions without needing to alter the compromised site, complicating enforcement measures, as defenders cannot merely seize or sinkhole an on-chain smart contract.

Independent scrutiny has revealed the same Base contract catering to a NoChain fake verification framework and ClickFix-style content.

When a Windows user interacts with the counterfeit Google reCAPTCHA overlay delivered by the contract, the page covertly copies mshta http://timelevel12[.]com/big into the clipboard, prompting the victim to initiate the command via the Win+R key combination.

This ingenious social-engineering scheme, tracked widely as ClickFix, turns the target into an active execution agent, adeptly circumventing security measures that rely on the identification of malicious downloads or attachments prior to activation.

Netskope Threat Labs attributed this activity to obsolete WordPress must-use plugins labeled site-helper-, which automatically deploy with the compromised sites.

Microsoft has issued warnings regarding the increasing exploitation of ClickFix and TerminalFix campaigns utilizing Windows utilities such as mshta, PowerShell, cmd, WMI, and scheduled tasks.

WordPress Sites Compromised

The harmful command fetches a polyglot file masquerading as an MP3 yet concealing an HTA application. Windows’ legitimate mshta.exe utility is responsible for processing the HTA content, which activates a hidden scheduled task and executes an encoded PowerShell command.

The subsequent phase allegedly circumvents Constrained Language Mode, manipulates AMSI scanning, and executes additional content directly in memory, as opposed to writing it to disk.

The malware further retrieves the Emmenhtal loader from gpuh. gravityzone[.]army, a domain posing as Bitdefender GravityZone.

Emmenhtal digs out an encrypted payload embedded within an image hosted by a legitimate content delivery network before reflectively loading the final PE into memory.

This endpoint payload, identified as Amatera—also referred to as ACR Stealer or AcridRain—specifically targets browser credentials and sensitive system information with alarming efficacy.

Research has also associated ClickFix implementations with blockchain-resolved scripts connected to Amatera dissemination.

Reportedly, Amatera’s command-and-control infrastructure utilizes encrypted DNS-over-HTTPS resolutions in conjunction with TLS, significantly obfuscating activities from network defenders.

The malware additionally communicates with gw. proxyvector[.]cc and could establish a root certificate, rendering affected systems potential conduits for credential theft and further intrusions.

Organizations are recommended to assess exposure to site-helper plugins, nochain-sw.js, the Base contract address, timelevel12[.]com, gpuh.gravityzone[.]army, i.ibb[.]co/3ytBLkY6/init-block.jpg, ultraspeed[.]pro/collect, and gw.proxyvector[.]cc.

Notably, the associated Service Worker and contract have been independently observed within active compromised site infrastructures.

For WordPress administrators, remediation steps should include the deletion of rogue plugins, scrutinizing modified JavaScript, changing credentials, and conducting audits of all administrative accounts.

Person wearing a WordPress t-shirt types on a keyboard at a desk with a computer monitor and a mug labeled WordPress OKULLU.

Importantly, simply cleaning the site may not suffice to shield visitors already impacted by the malicious Service Worker; users are advised to clear their site data and unregister any Service Workers linked to the affected domains.

Defenders should treat any CAPTCHA, browser alert, or verification page demanding users to paste commands into Run, Terminal, PowerShell, or Command Prompt as potentially malicious.

Mitigation strategies include blocking mshta.exe when feasible, limiting PowerShell usage, activating script-block logging, monitoring the creation of scheduled tasks, and examining suspicious blockchain RPC traffic to disrupt the chain before Amatera can infiltrate memory.

Indicators of Compromise (IOCs)

IndicatorTypeNotes
0x58460d0b3d4d6b03761c89120393c0c676676496EVM contract (Base 8453)Mutable payload/script registry and command-and-control
ultraspeed[.]proDomainEncrypted telemetry beacon host
https://ultraspeed[.]pro/collectURLECDH P-256 + AES-GCM encrypted telemetry endpoint
timelevel12[.]comDomainStage-2 MP3/HTA polyglot host
http://timelevel12[.]com/bigURLStage-2 payload fetched via mshta paste-and-run

Source link: Gbhackers.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading