📈 Get daily crypto insights that make you smarter about your money

WordPress Sites Weaponized in Mass Crypto Wallet Drainer Campaign

The cybersecurity landscape took a dark turn in early March 2024 as researchers uncovered a sprawling campaign that compromised over 2,000 WordPress websites, turning them into crypto-draining portals designed to steal funds and NFTs from unsuspecting visitors.

The Exploit Mechanics

The attack chain began with threat actors exploiting known WordPress vulnerabilities, particularly leveraging CVE-2023-6000, to gain unauthorized access to site administration panels. Once inside, attackers injected malicious JavaScript from the domain dynamic-linx[.]com, a command-and-control infrastructure previously identified by security firm Sucuri in related campaigns.

The injected code employed sophisticated evasion tactics. Before executing its payload, the script checked for a specific cookie — if absent, the malicious operation proceeded. This selective execution helped the malware evade detection by security scanners that do not maintain persistent cookie states during analysis.

Once loaded, the drainer script displayed fake pop-up NFT deals and cryptocurrency discount offers, creating a sense of urgency to lure visitors into connecting their wallets. The malware demonstrated broad compatibility across major wallet providers, including MetaMask, Coinbase Wallet, Ledger, Phantom, and WalletConnect.

Affected Systems

The campaign unfolded in multiple waves. The initial wave compromised roughly 1,000 WordPress sites to push crypto-draining malware promoted through YouTube videos and malvertising. Not satisfied with the reach, attackers then weaponized compromised sites into brute-forcing tools that attempted to crack admin passwords at other websites.

The second wave expanded the operation to approximately 1,700 brute-forcing websites, creating a self-propagating network of compromised infrastructure. This cascading approach allowed the attackers to exponentially grow their pool of infected sites without significant additional investment.

With Bitcoin trading at approximately 69,000 and Ethereum above 3,880 during this period, the potential payouts from successful wallet drains made this campaign particularly lucrative for the threat actors involved.

The Mitigation Strategy

Website owners running WordPress installations should immediately audit their sites for unauthorized JavaScript inclusions, particularly scripts loading from external domains. Key mitigation steps include updating all WordPress core files, themes, and plugins to their latest versions, implementing Web Application Firewalls, and conducting regular malware scans.

For end users, the attack underscores the importance of verifying website authenticity before connecting any crypto wallet. Browser extensions that block unauthorized scripts and DNS-level filtering can provide additional layers of protection against crypto drainer campaigns.

Lessons Learned

This campaign reveals an alarming trend: attackers are moving beyond simple phishing emails to compromise legitimate websites that users already trust. When a familiar blog or business site suddenly displays crypto offers, visitors are far more likely to engage than they would with an obvious scam domain.

The self-propagating nature of the attack, using compromised sites to brute-force additional targets, represents an evolution in crypto-theft infrastructure that security teams must account for in their threat models.

User Action Required

If you connected a wallet to any WordPress site in early March 2024 and noticed unexpected pop-ups or NFT offers, immediately revoke all token approvals, move your assets to a fresh wallet address, and monitor your transaction history for unauthorized transfers. Hardware wallet users should verify that all recent transactions were intentionally authorized on their physical device.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding crypto asset protection.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “WordPress Sites Weaponized in Mass Crypto Wallet Drainer Campaign”

  1. 2,000 sites and CVE-2023-6000 was the entry point. if youre running wordpress and havent patched this yet, honestly what are you doing

    1. the real issue is most of those site owners probably dont even know theyre compromised. its not like the injected script is visible to them

      1. most small business wordpress sites are managed by agencies that install a theme and forget about it. the site owner has no idea what CVE-2023-6000 even is. blaming them misses the point

        1. Rajiv M. blaming site owners misses the point completely. most WP installs are managed by agencies who charge $50/month and do zero maintenance. the incentive structure is broken

        2. 更新检查_

          Rajiv M. blaming site owners is harsh but the CVE was patched months before. at some point running unpatched critical infrastructure is negligence not victimhood

    2. the cookie check evasion is simple but effective. most scanners dont maintain session state so the malicious payload literally hides behind a single if statement. 2k sites and counting

      1. incidence_resp_

        xerosploit the cookie check was clever but the real trick was loading the drainer from an external domain. kill dynamic-linx and the payload is gone without touching the wp install

        1. incidence_resp_ killing dynamic-linx doesnt help because the injected JS is still on 2000 sites. the payload survives even after the C2 domain goes down

        2. static_payload

          incidence_resp_ killing dynamic-linx removes the payload from 2000 sites instantly though. one domain takedown and every compromised WP install goes clean. way faster than patching each site individually

      2. cookie_baker_

        the cookie check was clever tbh. one if statement that defeats every automated scanner that doesnt maintain session state. simple but devastating

  2. 2,000 sites and most owners had no idea. the average wp install gets updated maybe once a year if youre lucky. this attack surface is only getting worse

  3. dynamic-linx domain has been flagged since late 2023 and they still managed to hit 2k sites. infrastructure takedowns are way too slow

    1. dynamic-linx has been cycling through new domains every few weeks. kill one and three pop up. whack a mole with infinite respawns because the wp sites hosting the scripts keep multiplying

      1. cve_archivist_

        patch_alert_ dynamic-linx cycling domains every few weeks is whack-a-mole. the real fix is WP auto-updates being mandatory but that breaks custom plugins so itll never happen

  4. Mira Kowalczyk

    fake NFT deals as the lure is smart because it targets people already comfortable connecting wallets. the drainer script drained both ETH and ERC-20 tokens in a single approval. brutal efficiency

  5. wp_host_hell_

    CVE-2023-6000 was patched months before this campaign and 2000 sites were still vulnerable. the WP plugin update problem is basically unsolvable at this point

    1. wp_host_hell_ the patch exists but the site owners dont know they need it. most small business WP installs havent seen an update since the day they launched

  6. 2000 WordPress sites compromised via CVE-2023-6000 and most WP admins still dont patch plugins. the attack surface is insane

  7. the cookie check before executing the drainer payload was smart evasion. most automated scanners dont persist cookies so the malware literally hides from security tools

  8. 2000 WP sites hosting drainer scripts and the C2 domain dynamic-linx was flagged for months before takedown. the response time for crypto-specific infrastructure abuse is measured in quarters not hours

  9. fake NFT deals as the lure is targeting exactly the people who already connected wallets to openSea clones. the drainer exploits trust built by legitimate marketplaces

  10. CVE-2023-6000 was patched months before this campaign. 2000 sites still got compromised because nobody updates their WP installs. the patch exists, the laziness also exists

    1. Niklas P. most WP site owners dont even know what version theyre running. the agency that built their site in 2019 sure isnt monitoring CVEs

  11. fake NFT deals as the lure targeting people who already trust OpenSea clones. the social engineering was more sophisticated than the actual exploit

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,926.00+0.2%ETH$1,915.29-0.2%SOL$76.56+0.3%BNB$603.66+0.3%XRP$1.03-0.5%ADA$0.1950-0.6%DOGE$0.0699-0.2%DOT$0.8060-0.1%AVAX$6.51+0.5%LINK$8.24-0.8%UNI$4.01+0.1%ATOM$1.38-0.1%LTC$45.43-1.6%ARB$0.0797+3.0%NEAR$1.66+2.1%FIL$0.7008-1.5%SUI$0.6927+0.1%BTC$64,926.00+0.2%ETH$1,915.29-0.2%SOL$76.56+0.3%BNB$603.66+0.3%XRP$1.03-0.5%ADA$0.1950-0.6%DOGE$0.0699-0.2%DOT$0.8060-0.1%AVAX$6.51+0.5%LINK$8.24-0.8%UNI$4.01+0.1%ATOM$1.38-0.1%LTC$45.43-1.6%ARB$0.0797+3.0%NEAR$1.66+2.1%FIL$0.7008-1.5%SUI$0.6927+0.1%
Scroll to Top