A spam-injecting malware is targeting WordPress site owners by disguising itself as a legitimate license key for a WordPress design theme. The malware is housed in base64-encoded text within the $token variable. Malware obfuscation continues to be a creative hotspot for cybercriminals, with new techniques cropping up on a regular basis. A customer opened a malware removal ticket reporting some weird spam URLs injected onto their WordPress website s website The malware displays spam links to most user agents with a few exceptions.
Source: https://threatpost.com/malware-wordpress-license-key/141315/

