How common is the Chinese Wordpress Malware Hack?

RichMoney

Junior Member
Joined
Jan 29, 2019
Messages
141
Reaction score
56
My websites got infected with this shit. I had to manually clean around 20 Wordpress sites from the same server.
The problem is still persisting and Bluehost does not really offer any help unless I pay for their Security Program.

My question is, for anyone who ever encountered or went through this bullshit:

1. Is it possible to fully get rid of the malware?
2. What could be security breaches into Wordpress ? ( nulled or cracked themes or plugins, weak passwords, cheap SSL ? )
3. How are the hackers benefiting from this ?
 
I've just been through the same nightmare, but thankfully it's over for me now. Unfortunately, I also have BlueHost and I'm switching as soon as my plan expires.

I made a post on here as well, you can see it here:
https://www.blackhatworld.com/seo/my-website-has-been-hacked-i-need-help.1486885/
It's no use just deleting and editing the files BlueHost's malware scanner and Wordfence find, you have to check your plugin files against the original ones - and that's a shitty job!

I was lucky enough to find a guy on UpWork who knew exactly what to do and was incredibly thorough. Today, I no longer have malware. His name is Salman N.
https://www.upwork.com/freelancers/~0185e099b0a2828d4b
Good luck :)
 
Oh man, I'm incredibly thankful for this solid advice!

It has been a rollercoaster so far but fuck it, i'm laying a plan asap.
 
Here's the thing with some of these malware attacks, they'll get in your wp database or replace actual wp files (not involved with the initial entry-point/plugin/theme) with obfuscated code that'll just re-install their malware even after you've replaced/updated the bad theme/plugin. You should export your wordpress database and run a couple searches for things like php or variables that would indicate a breach. Then do a clean install. Here's a good article on doing just that:
https://wpdatatables.com/scan-wordpress-database-for-malware/(also this time around make sure to take precautions like hardening the permissions for your wp-content folder, turning on auto-updates, etc..)
 
What version of wordpress or plugin was the one that caused the intrusion?
 
Back
Top