Cybercriminals Exploit Pastebin to Distribute Malicious Backdoor Code
The well-known code-sharing platform, Pastebin, initially designed for developers to exchange programming scripts and store snippets, has recently fallen victim to exploitation by cybercriminals. Created over a decade ago, the website has transitioned into a tool used by hackers to target millions of users by distributing stolen data and malware.
Hackers have turned to a familiar technique of compromising websites and hosting malicious software. Recent investigations reveal their latest strategy involves leveraging Pastebin to spread harmful backdoor scripts across a wide array of targets. A recent blog post by Denis Sinegubko, a senior malware researcher at Sucuri, highlights how these attacks utilize vulnerabilities in outdated versions of the RevSlider, a widely used premium plugin for WordPress.
This particular WordPress plugin often comes integrated with various website themes, a factor that leaves many site owners unaware of its presence. Once attackers identify a site running the vulnerable plugin, they exploit a second flaw within RevSlider to inject their malware into the target’s system. This method allows for a more efficient approach to compromise numerous websites simultaneously.
Sinegubko emphasized that “technically, the criminals used Pastebin for what it was built for – to share code snippets.” However, the nature of the code being disseminated is malicious and directly involved in illegal hacking activities. Security researchers have uncovered segments of code that utilize a Base64-encoded variable to inject harmful scripts directly into WordPress core files, particularly the wp-links-opml.php file. This harmful code is sourced from Pastebin, cleverly disguising its origin through the use of a parameter known as wp_nonce_once, which typically serves to protect against unwanted requests.
The deceptive use of the wp_nonce_once parameter complicates the detection and blocking of this malicious link, while also providing adaptability to the backdoor, allowing it to execute various code snippets from Pastebin. Remarkably, the malware is capable of fetching and executing code that may not even exist at the time of the initial injection — all that is required is the passage of a request through the compromised file.
As of now, the extent of this malicious backdoor’s proliferation remains uncertain; however, with Pastebin boasting around 1.5 million active user accounts as of last year, the threat posed is substantial. Pastebin, which originated in 2002 as an open forum for coding collaboration, has increasingly drawn the attention of hackers. The platform is frequently utilized for distributing information stolen from prominent corporations, with numerous entries linked to malware attacks that may contain encrypted data or base64-encoded malicious components.
In a related incident last month, Sucuri identified another malware strain, known as SoakSoak, targeting outdated versions of the Slider Revolution plugin. Google responded by blacklisting over 11,000 sites identified as spreading this malware. The evolving tactics of cyber adversaries underscore the importance of proactive security measures. Business owners must remain vigilant about the potential vulnerabilities in their systems, particularly with widely used plugins, to safeguard their digital assets against increasing threats.
By drawing insights from the MITRE ATT&CK framework, business owners can better understand the tactics involved in this type of cyberattack, such as initial access through compromised plugins, persistence via backdoor installations, and privilege escalation when further exploiting the system. The landscape of cybersecurity threats continues to evolve, making it imperative for organizations to adopt comprehensive security protocols to counteract these risks effectively.