No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Phishing Operators Make Ready Use of Abandoned Websites for Bait

August 15, 2023
in Protection
0
informa



Attackers are increasingly targeting abandoned and barely maintained websites for hosting phishing pages, according to a new study from Kaspersky.

In many cases, phishers’ focus is on WordPress sites because of the sheer number of known vulnerabilities in the widely used content management system and its numerous plug-ins.

Large Number of Compromised Websites

Researchers at Kaspersky recently counted 22,400 unique WordPress websites that threat actors had compromised between mid-May 15 and the end of July to host phishing pages. The number included websites that attackers were literally able to walk into because they provided open access to the control panel, as well as sites that attackers had to break into via vulnerability exploits, credential theft, and other means. Kaspersky detected 200,213 attempts by users to visit phishing pages that threat actors had hosted on these websites.

“Both long-neglected and actively maintained websites may be targeted this way,” Kaspersky said in a report this week. “In particular, hackers tend to compromise smaller websites whose owners cannot immediately recognize their presence.”

Phishing continues to be one of the most popular initial access vectors for attackers because of just how successful they have been with it. Fundamental to that success is their ability to create convincing websites and pages that users are likely to trust enough to share their credentials and other sensitive information.

Kaspersky researchers found that to improve the con, phishing operators sometimes leave a compromised website’s main functionality untouched even as they publish phishing pages on the site. “A visitor would never guess the site has been hacked: every section is where it is supposed to be, and only relevant information can be seen,” Kaspersky said. Instead, the attackers hide their phishing pages inside new directories that are not accessible on the website’s menu, the security vendor said.

Easy Pickings

Long neglected domains are also attractive for attackers because phishing pages can remain active on them for a long period as well. This can be especially significant for attackers given the relatively brief lifecycle of phishing pages in general. In December 2021, Kaspersky released a report that summarized its analysis of the lifecycle of phishing pages. The study showed that 33% of phishing pages became inactive within a single day of going live. Of the 5,307 phishing pages that Kaspersky researchers analyzed for the study, 1,784 stopped working after the first day, with many becoming inactive in just the first few hours. Half of all pages in the study ceased to exist after 94 hours.

For threat actors, the task of breaking into abandoned and barely maintained websites is often simple because of the security holes that exist in the environment. Just last year, researchers and vendors disclosed a total of 2,370 vulnerabilities in WordPress and plugins. The most common of these include cross-site scripting, authorization bypass, SQL injection, and information disclosure.

Kaspersky found that typically, when an attacker breaks into a WordPress site via a vulnerability, they upload a WSO Web shell, which is a malicious shell script that allows attackers complete remote control over the website. The attackers then use the Web shell to break into the compromised website’s admin panel and start putting fake pages on it. They also use the control panel to store credentials, bank card data, and other sensitive information that a user might be tricked into entering on the website. When an attacker leaves access to the control panel open, anyone on the Internet can then get access to the data, Kaspersky said.

“Seasoned cybercriminals hack legitimate websites as a way of setting phishing traps,” Kaspersky said. “Both long-neglected and actively maintained websites may be targeted this way,” especially when the websites are small, and the operators are ill-equipped to detect malicious activity.

Kaspersky’s blog offered tips on how WordPress website operators can detect if an attacker has hacked their website and is using it to host phishing pages.

Editorial Team

Editorial Team

Related Posts

I Went to 'The Inspired Home Show' As a New Homeowner, and It Forever Changed How I'll Shop
Protection

I Went to ‘The Inspired Home Show’ As a New Homeowner, and It Forever Changed How I’ll Shop

March 13, 2026
The Five Coolest Houseware Innovations I Saw at The Inspired Home Show's 'Inventors Corner'
Protection

The Five Coolest Houseware Innovations I Saw at The Inspired Home Show’s ‘Inventors Corner’

March 13, 2026
10 Shows Like 'From' You Should Watch Next
Protection

10 Shows Like ‘From’ You Should Watch Next

March 13, 2026
This LG Soundbar System With a Subwoofer and Rear Speakers Is Half Off Right Now
Protection

This LG Soundbar System With a Subwoofer and Rear Speakers Is Half Off Right Now

March 13, 2026
This 75-Inch Hisense Mini-LED TV Is $400 Off Right Now
Protection

This 75-Inch Hisense Mini-LED TV Is $400 Off Right Now

March 13, 2026
10 Hacks Every Peloton User Should Know
Protection

10 Hacks Every Peloton User Should Know

March 13, 2026
Load More
Next Post
Live news: Evergrande EV unit shares jump after Dubai deal

Live news: Evergrande EV unit shares jump after Dubai deal

Popular News

  • Markets hopes for Fed interest rate cuts are rapidly fading away

    Markets hopes for Fed interest rate cuts are rapidly fading away

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • United’s stock rallies as airline’s perks and loyalty strategy pays off

    0 shares
    Share 0 Tweet 0
  • Cash Isa battle sees Trading 212 hike best rate TWICE in one week – how to bag 5.1%

    0 shares
    Share 0 Tweet 0
  • The Best Last-Minute Cyber Monday Deals on Fitness Trackers, Watches, and Home Gym Equipment

    0 shares
    Share 0 Tweet 0

Latest News

TRUMP

US President To Host Exclusive Luncheon For TRUMP Holders April 25 At Mar-a-Lago

March 13, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure President Donald Trump is preparing to host...

India to hold off on US trade deal amid new probe, sources say

India to hold off on US trade deal amid new probe, sources say

March 13, 2026
0

India to hold off on US trade deal amid new probe, sources say

Bitcoin Outperforms Macro Assets in Iran Conflict as $72,000 Returns

Bitcoin Outperforms Macro Assets in Iran Conflict as $72,000 Returns

March 13, 2026
0

Bitcoin (BTC) hit eight-day highs into Friday’s Wall Street open as markets awaited key US inflation cues.Key points:Bitcoin shows resilience...

‘Healthcare is important to me’: I’m worried about relocating to Florida from New Jersey. Are hospitals there under stress?

‘Healthcare is important to me’: I’m worried about relocating to Florida from New Jersey. Are hospitals there under stress?

March 13, 2026
0

“The issue is not the weather, high insurance premiums or high maintenance fees.”

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.