{"id":6016,"date":"2025-08-09T10:03:36","date_gmt":"2025-08-09T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/09\/huge-wave-of-malicious-efimer-malicious-script-attack-users-via-wordpress-sites-malicious-torrents-and-email\/"},"modified":"2025-08-09T10:03:36","modified_gmt":"2025-08-09T10:03:36","slug":"huge-wave-of-malicious-efimer-malicious-script-attack-users-via-wordpress-sites-malicious-torrents-and-email","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/09\/huge-wave-of-malicious-efimer-malicious-script-attack-users-via-wordpress-sites-malicious-torrents-and-email\/","title":{"rendered":"Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email"},"content":{"rendered":"<p>    Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign dubbed \u201cEfimer\u201d has emerged as a significant threat to cryptocurrency users worldwide, employing a multi-vector approach that combines compromised WordPress websites, malicious torrents, and deceptive email campaigns.<\/p>\n<p>First detected in October 2024, this ClipBanker-type Trojan has evolved from a simple cryptocurrency stealer into a comprehensive malicious infrastructure capable of self-propagation and widespread distribution.<\/p>\n<p>The malware\u2019s name derives from a comment found within its decrypted script, and its primary objective centers on cryptocurrency theft through clipboard manipulation.<\/p>\n<p>When users copy <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallet<\/a> addresses, Efimer silently replaces them with attacker-controlled addresses, effectively hijacking transactions.<\/p>\n<p>Beyond its core functionality, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> demonstrates remarkable versatility by incorporating additional modules for WordPress site compromise, email address harvesting, and spam distribution.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJqQxUKsglwCQor0Dg5uepdh4sJe94tGgXPTzk_QD8WYPkcOuoDv6bRd9bj4DfEzVIkv7p2qK0cJ4HSCKaLAMh82-QSa5naaUMptgDVrmbvfc0G0e3ytgyCLuP3WIc9MBad5A14iFMwZqjnZ5eZllnlDRST8NuXixNNi_ssAraTZdeQL4QlqDJjobRWy8\/s16000\/Spam%2520email%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Spam email (Source \u2013 Securelist)<\/figcaption><\/figure>\n<\/div>\n<p>Securelist analysts <a href=\"https:\/\/securelist.com\/efimer-trojan\/117148\/?utm_source=dlvr.it&amp;utm_medium=twitter\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that Efimer has impacted over 5,000 users across multiple countries, with Brazil experiencing the highest concentration of attacks affecting 1,476 users.<\/p>\n<p>The malware\u2019s reach extends across India, Spain, Russia, Italy, and Germany, indicating a global threat landscape.<\/p>\n<p>What distinguishes Efimer from conventional malware is its ability to establish complete malicious infrastructure, enabling sustained attacks and continuous expansion of its victim base.<\/p>\n<p>The attack vectors demonstrate sophisticated <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> techniques. Email campaigns impersonate lawyers from major companies, falsely claiming domain name trademark infringement and threatening legal action unless recipients change their domain names.<\/p>\n<p>These emails contain password-protected ZIP archives with names like \u201cDemand_984175.zip\u201d containing malicious WSF files.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEirZC-BZt2W9FWxT3TOTOyV5-ug4k96geB8LAn7V4zQa0FCmOpYuKrEoJc5Z_hPyljU7WpVBh7yMjzSuwCA2IXolG8-K57QzjuYMt_5Ebj0tFFNbs3G7EYwFgKGwOm2mACyIHlxMn5VLOiOMjDCczpVsMLkWyUccPy_44lKBVLcSKk53dtAmJGJrQ09CZg\/s16000\/The%2520p_timer%2520variable%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The p_timer variable (Source \u2013 Securelist)<\/figcaption><\/figure>\n<\/div>\n<p>Simultaneously, attackers compromise WordPress sites to post fake movie torrents, particularly targeting popular releases like \u201cSinners 2025,\u201d which contain executable files masquerading as media players.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-infection-mechanism-and-persistence\"><strong>Technical Infection Mechanism and Persistence<\/strong><\/h2>\n<p>The infection process begins when victims execute the malicious WSF or EXE files, triggering a complex multi-stage deployment.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjDZ8p43Y0JUr-SDsIp1Xc7aSJPwcAPbX1XMnn-KJDDUHLYN92bUFJKZsZAEE83xbCeT5obOCOJ5qE7RTbf5lMUqy4ks0XvkN7rHOt2VboLEbpsSJ4kTg6b7-dtmrX1eyailMVBY1tAci7b2CjjhJX_Z0AF0G-qEE-8mCf_b6wsPFO4m1QJfYhqM_SrjPk\/s16000\/The%2520script%25E2%2580%2599s%2520operation%2520cycle%2520involves%2520both%2520the%2520brute-force%2520code%2520and%2520the%2520handler%2520for%2520its%2520core%2520logic%2520%28Source%2520-%2520Securelist%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The script\u2019s operation cycle involves both the brute-force code and the handler for its core logic (Source \u2013 Securelist)<\/figcaption><\/figure>\n<\/div>\n<p>Upon execution, Efimer first checks for administrator privileges by attempting to write to a temporary file at <code>C:WindowsSystem32wsf_admin_test.tmp<\/code>.<\/p>\n<p>If successful, the malware adds exclusions to <a href=\"https:\/\/cybersecuritynews.com\/windows-defender-enhancements\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a> for the <code>C:UsersPubliccontroller<\/code> folder and system processes including <code>cmd.exe<\/code> and the WSF script itself.<\/p>\n<p>The malware establishes persistence through different methods depending on user privileges. For privileged users, it creates a scheduled task using a controller.xml configuration file, while limited users receive registry entries in <code>HKCUSoftwareMicrosoftWindowsCurrentVersionRuncontroller<\/code>.<\/p>\n<p>The core payload, controller.js, operates as the primary Trojan component, continuously monitoring clipboard contents every 500 milliseconds while implementing sophisticated evasion techniques, including immediate termination if Task Manager is detected running.<\/p>\n<p>Efimer\u2019s communication infrastructure relies on the Tor network, downloading the Tor proxy service from multiple hardcoded URLs hosted on compromised WordPress sites.<\/p>\n<p>The malware generates unique GUIDs following the format \u201cvs1a-\u201d for victim identification and maintains communication with command-and-control servers at intervals of 30 minutes to avoid detection while ensuring persistent connectivity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Equip your SOC with full access to the latest threat data from\u00a0<strong>ANY.RUN TI Lookup<\/strong>\u00a0that can Improve incident response -&gt;\u00a0<strong><a href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn_aug&amp;utm_medium=article&amp;utm_campaign=how-to-get-real-time-iocs&amp;utm_content=feeds-cta1&amp;utm_term=050825#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 14-day\u00a0Free\u00a0Trial<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/huge-wave-of-malicious-efimer-malicious-script-attack-users\/\">Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/huge-wave-of-malicious-efimer-malicious-script-attack-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email A sophisticated malware campaign dubbed \u201cEfimer\u201d has emerged as a significant threat to cryptocurrency users worldwide, employing a multi-vector approach that combines compromised WordPress websites, malicious torrents, and deceptive email campaigns. First detected in October 2024, this ClipBanker-type Trojan [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6016","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6016"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6016"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6016\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}