216.73.216.6

Malicious JavaScript Injects Fullscreen Iframe On a WordPress Website

· Published 14/08/2025 08:07 · Modified 14/08/2025 11:02

Export JSON

Essential information

Published
14/08/2025 08:07
Modified
14/08/2025 11:02
Tags
2025-08-14 anti-debugging fake captcha fullscreen overlay iframe injection javascript powershell exploitation wordpress wpcode plugin
Related entities
6 observables, 1 techniques (mitre)

Description

A -based malware campaign has been discovered affecting compromised websites. The malware injects a fullscreen iframe that loads content from suspicious external domains, aiming to force users to view unsolicited content for ad fraud, traffic generation, or social engineering. The infection was found embedded in the wp_options database table, exploiting the . The malicious script uses advanced evasion techniques like , function hijacking, and localStorage abuse. It selectively targets Windows users on specific browsers, displaying a fake Cloudflare CAPTCHA page that prompts users to run a suspicious PowerShell command. This attack not only intrudes on user experience but also poses significant security risks, potentially leading to system compromise and damage to website reputation.

External references