Follow us on Social Media

Nederlands NL English EN

Thousands of WordPress sites are spreading malware via fake updates!

More than 6.000 WordPress websites have been hit by malware that tricks visitors into downloading fake Google Chrome updates. The attacks, which began in June 2023, use stolen admin credentials to install malicious plugins. These plugins display a pop-up that encourages visitors to download a fake browser update. However, the “update” turns out to be an infostealer targeting […] Continue reading

  • 10+ years of experience
  • 100% Satisfaction Guarantee
  • Free quote within 24 hours
  • Microsoft partner
  • No contracts
  • Complete ICT management
  • Lowest price guarantee

Request a no-obligation quote →

Thousands of WordPress sites are spreading malware via fake updates!
Thousands of WordPress sites are spreading malware via fake updates!
Thousands of WordPress sites are spreading malware via fake updates!
Thousands of WordPress sites are spreading malware via fake updates!

We work on a punch card basis. You buy a bundle of hours, use us whenever you want, and only pay for the time we actually spend. 🙂 No waste, no ongoing monthly costs.

Watch directly →

Request an IT quote without obligation within 24 hours.

Starter

€95

120 minutes all year round

Ideal for: 1-3 employees

Order

  • Free advice
  • Organization-wide
  • No starting rate
  • Valid for 1 year
  • Mon-Fri: 09:00 – 17:00
  • Discount on rate at location

Professional

€179

270 minutes all year round

Ideal for: 3-6 employees

Order

  • Free advice
  • Organization-wide
  • No starting rate
  • Valid for 1 year
  • Mon-Fri: 09:00 – 17:00
  • Discount on rate at location
Thousands of WordPress sites are spreading malware via fake updates!

Thousands of WordPress sites are spreading malware via fake updates!

More than 6.000 WordPress websites have been hit by malware that tricks visitors into downloading fake Google Chrome updates. The attacks, which began in June 2023, use stolen admin credentials to install malicious plugins. These plugins display a pop-up encouraging visitors to download a fake browser update. However, the “update” turns out to be an infostealer, aimed at stealing sensitive information like passwords and login credentials.

For WordPress admins and users, it is crucial to be aware of this threat and take the necessary security measures. These cyberattacks highlight the importance of strong passwords, regular updates, and scanning your site for suspicious activity.

How does this attack work?

The malware campaign that infected thousands of WordPress websites follows several key steps:

  • To access the site: Attackers break in through weak or stolen administrator passwords.
  • Installation of malicious plugins: Malicious plugins are installed, causing visitors to see fake browser updates.
  • Showing fake pop-ups: Visitors will see notifications asking them to update their browser.
  • Infection of the visitor: Clicking on the fake update leads to the installation of malware on the visitor's device.
  • Data theft: The malware collects passwords and sensitive information and sends them to the attackers.

The danger of this attack is that both the administrators of the infected sites and their visitors are at risk of data theft.

Why are WordPress sites targeted?

WordPress is one of the most popular content management systems (CMS) in the world, making it an attractive target for cybercriminals. Many website owners ignore updates or use outdated plugins, creating security holes that attackers can exploit. Additionally, passwords are often reused or not stored securely, making it easier for hackers to gain access.

Here are some reasons why WordPress sites are often targeted:

  • Great popularity: WordPress has millions of users worldwide, making it an attractive target.
  • Outdated software: Many websites run on older versions of WordPress, which pose security risks.
  • Weak security: Administrators sometimes use simple or reused passwords.
  • Using unsecured plugins: Malicious plugins can be easily installed when the site is not properly maintained.
  • Lack of updates: Many WordPress sites are not updated regularly, making them vulnerable to exploits.

How can you protect your WordPress site?

There are a number of steps you can take to protect your WordPress site from these types of attacks:

  • Use strong passwords: Avoid simple passwords and password reuse.
  • Enable two-factor authentication (2FA): This adds an extra layer of security, even if your password is stolen.
  • Update regularly: Make sure your WordPress, themes, and plugins are up to date to prevent security vulnerabilities.
  • Install security plugins: Use a reliable security plugin to detect suspicious activities.
  • Make regular backups: Always keep a recent backup of your site so you can quickly recover in the event of an attack.

By taking proactive measures, you can drastically reduce the chance of a successful attack. Many attacks target weak security measures that are easily preventable with the right tools and methods.

Closing note

If you run a WordPress site, it’s crucial to take your security seriously. Cyberattacks are becoming increasingly sophisticated and are targeting every possible vulnerability. Using strong passwords, two-factor authentication, and regular updates are some of the best ways to keep your site safe. Additionally, it’s a good idea to install a reliable security plugin and back up your site regularly.

If you are unsure about how to secure your site, consider a professional WordPress maintenance subscription. Flexamedia offers comprehensive services to keep your site secure and up-to-date.

Click here to learn more about securing your WordPress site.

An all-round ICT company in South Holland

ICT company in Vlaardingen

ICT services in Vondelwijk

Voorburg ICT solutions

Voorschoten IT experts

Voorhout ICT company

Waddinxveen IT services

Wassenaar ICT specialists

ICT services in Zoetermeer

Bennebroek ICT solutions

ICT expertise in Spijkenisse

Nieuwkoop IT support

Leiderdorp ICT services

Oude Wetering IT company

Alblasserdam IT solutions

ICT experts in Barendrecht

ICT services in Ypenburg

Bergschenhoek IT services

Utrecht ICT solutions

De Lier ICT support

ICT expertise in Hoofddorp

Bodegraven IT services

Katwijk aan Zee IT company

ICT services in Goedereede

Berkel and Rodenrijs ICT

Alphen aan den Rijn IT

ICT services in Benthuizen

Bleiswijk ICT solutions

ICT specialists in Bloemendaal

Boskoop IT services

ICT expertise in Brielle

Capelle aan den IJssel ICT

ICT solutions in Delfshaven

Capelle West IT services

ICT specialists in Delft

Haastrecht IT support

Gouda ICT solutions

ICT services in Heerjansdam

Groenswaard IT company

Heinenoord IT services

ICT specialists in Hellevoetsluis

Hoek van Holland IT

Hendrik Ido Ambacht ICT

Hillegom IT solutions

ICT expertise in Honselersdijk

ICT services in Oranjewijk

Katwijk aan den Rijn ICT

Leiden ICT solutions

ICT specialists in Lisse

ICT expertise in Maassluis

Maasdijk IT services

Mijnsheerenland IT company

IT services in Monster

Naaldwijk ICT solutions

ICT expertise in Nieuwenhoorn

Noordwijk Within IT

ICT services in Nieuw Helvoet

Kwintsheul IT support

Krimpen aan den IJssel ICT

Leimuiden IT services

Reeuwijk ICT solutions

ICT services in Rhoon

Rijnsburg IT support

Rijswijk ICT solutions

ICT experts in Ridderkerk

Rotterdam IT services

New Lekkerland ICT

Noordwijkerhout IT

Oegstgeest ICT solutions

ICT services in Poeldijk

Oud Beijerland IT

Pijnacker IT services

ICT experts in Scheveningen

Sassenheim IT solutions

ICT services in Schiedam

ICT expertise in 's Gravenzande

Benefit from our total solutions in ICT support

Other articles

How do you fix common system errors?

Ever experience those annoying system errors that can completely ruin your day? Well, you're not alone! Those moments when your computer decides to time out just when you need it most. But don't panic,...

Read more

Best cloud management tools? An overview.​

When it comes to managing your online empire, good cloud management tools are indispensable. Whether you’re just starting to explore the wide world of cloud computing or you’re already the captain of a vast digital empire, finding the right...

Read more