CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Global Infostealer Campaign Exploits Compromised WordPress Sites

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A widespread cybercriminal campaign has compromised over 250 legitimate WordPress websites across 12 countries to deliver infostealer malware. The attackers exploit user trust in these sites to infect visitors with malware such as Vidar Stealer, Impure Stealer, Vodka Stealer, and Double Donut. The campaign, active since December 2025, uses fake Cloudflare Captcha pages and ClickFix social engineering techniques to trick users into running malicious code, ultimately stealing sensitive data including login credentials and financial information.

Timeline

  1. 11.03.2026 16:45 1 articles · 2h ago

    Compromised WordPress Sites Used in Global Infostealer Campaign

    A widespread cybercriminal campaign has compromised over 250 WordPress sites across 12 countries to deliver infostealer malware. The campaign, active since December 2025, uses fake Cloudflare Captcha pages and ClickFix social engineering techniques to infect visitors with malware such as Vidar Stealer, Impure Stealer, Vodka Stealer, and Double Donut. The goal is to steal sensitive data, including login credentials and financial information.

    Show sources

Information Snippets