ADVERTISEMENT

Unveiling the Balada injector: a malware epidemic in WordPress

Learn the shocking truth behind the Balada Injector campaign and find out how to protect your organization from this relentless viral invasion.

WordPress malware epidemic

By Shutterstock

Adam Kohnke
Adam Kohnke Contributor
June 13, 2023 Updated: June 14, 2023 5 min read

What is Balada?

Basic Balada Injector workflow
Basic Balada Injector workflow and capabilities against a WordPress CMS.

Identifying Balada injections

ADVERTISEMENT
cdn.statisticline[.]com/scripts/sway.jsactraffic[.]comimportraffic[.]com
collectfasttracks[.]comfollowmyfirstone[.]comdigestcolect[.]com
primarylocationgo[.]comstarttrafficc[.]combuyittraffic[.]com
cutttraffic[.]comdexterfortune[.]comjockersunface[.]com
destinyfernandi[.]comrequestfor4[.]combalanceforsun[.]com

Exploitation walkthrough

The various elements and functions within Elementor Pro
The various elements and functions within Elementor Pro, that facilitate website compromise when using version 3.11.6 or earlier.

Defensive control considerations

  • Routinely audit necessary plugins, themes or software strictly necessary for web application operations. Remove all unnecessary or unused software.
  • Conduct internal and routine penetration testing or similar assessments against web applications to identify exploitable weaknesses before Balada does.
  • Enable File Integrity Monitoring (FIM) against critical system files.
  • Heavily restrict access to sensitive files like wp-config, website backup data, log files or database archives and ensure strong data retention policies purge older versions of this data when no longer needed.
  • Disable unnecessary or insecure server services and protocols like FTP.
  • Subscribe to security alerts via US CISA, MS-ISAC or other reputable threat intelligence services to learn about critical software and system vulnerabilities.

Summary

ADVERTISEMENT