Website Xubuntu hacked with links on the download page replaced with malware

The official website of the Xubuntu distribution has been compromised by unknown attackers, who replaced links to torrents on the download page with a file "https://xubuntu.org/wp-content/Xubuntu-Safe-Download.zip". As a result, the download page now only contains links to a malicious archive and available mirrors. The Xubuntu developers have not yet commented on the situation, but several hours ago they deleted the malicious archive and blocked access to the "xubuntu.org/download/" section, redirecting to the main page of the site.

The archive.org service captured copies of xubuntu.org on October 11 and 18 — on October 11, the page had not yet been altered, while on October 18, the malicious change was already present. The project's mirrors, through which ISO images are distributed, appear unaffected based on preliminary checksum analysis and correspond to the standard cdimage.ubuntu.com. Signs of compromise have only been noticed on the xubuntu.org website, which uses WordPress content management system. It is assumed that the hack was carried out through an outdated WordPress plugin containing a vulnerability.

The archive "Xubuntu-Safe-Download.zip" distributed by the attackers contains an executable file for Windows, which is presented as the Xubuntu installer. Scanning the specified file using VirusTotal reveals the presence of malware.

When the executable file is launched, a fake interface is displayed, including fields for selecting the distribution version to download and the type of package, as well as a button labeled "Generate Download Link." When clicked, a file named "elzvcf.exe" is saved in the "AppData Roaming" directory, and its execution is set to run at system startup in the Windows registry. Preliminary information suggests that the malware analyzes clipboard data and replaces addresses of Bitcoin, Litecoin, Ethereum, Dogecoin, Tron, Ripple, and Cardano wallets with those belonging to the attackers.

Website Xubuntu hacked with links on the download page replaced with malware

Interestingly, on September 10, one user complained about a blog post on the xubuntu.org site advertising a casino, but this blog post was promptly deleted, and the incident did not escalate (it was probably considered that the advertisement was inserted by malware on the user's side).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster