Skip to main content

WordPress Keylogger and Crypto Miner Attacks

Attackers are targeting WordPress websites to install keystroke logging and cryptocurrency miner malware.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Attackers are targeting WordPress websites to install keystroke logging and cryptocurrency miner malware.

Affected platforms

The following platforms are known to be affected:

Threat details

The malicious code is installed by exploiting known vulnerabilities in insecure versions of WordPress, including themes and plugins. The keylogger is injected into the dashboard login page, and the CoinHive miner is injected into the site's front end pages. These can then steal passwords and other data, and reduce system performance.


Remediation steps

Type Step
  • To help prevent an infection, update WordPress to the latest version (including any themes and plugins that have been installed).
  • To detect an infection, check whether suspicious scripts are being loaded on the dashboard login page.

Last edited: 17 February 2020 12:57 pm