It’s not clear how exactly the attackers are compromising WordPress sites, but it’s likely to be a combination of different vectors. It’s also not yet been confirmed that all of the attacks we’re discussing here are carried out by the same group, although it is considered likely.
Once sites are compromised, the attackers are leveraging their access for a variety of purposes. It appears that users are being redirected to sites that host advertising that serves malicious code.
According to Malwarebytes, the advertising laden sites are a diversion from the true purpose of the attacker, which is to infect users’ machines with malware. Users are redirected to servers hosting the Nuclear exploit kit, which attempts to exploit vulnerabilities in software on the user’s system — typically Flash, Java, and other vulnerability prone software — to install malware, which includes the Teslacrypt ransomware package. Victims will have their data encrypted so that they can be extorted to hand over cash in exchange for the decryption key.
The infection may not be apparent to site administrators or regular site users because only first-time users are redirected — a common tactic of online criminals to reduce the chances of detection.
While it’s not clear exactly how these attacks are compromising WordPress sites, WordPress site owners should ensure that they follow all WordPress security best practices to minimize the likelihood of a successful attack.
Site owners should ensure that access credentials to their servers include long and random passwords. Site owners should check WordPress login credentials, but they should also ensure that any SSH and FTP logins also use secure passwords.
Where possible, WordPress users should implement two-factor authentication on their site. TFA considerably decreases the risk that an attacker can carry out a successful brute force attack.
Out-of-date WordPress installations and plugins are often the vector used by attackers to compromise sites. Regularly updating their WordPress site is one of the most important things a WordPress user can do to keep it safe.