KashmirBlack is the new botnet that has infected over 200,000 websites

Image: Rack Solutions

A new botnet, named KashmirBlack, has been identified to have infected approximately 230,000 websites running popular content management systems (CMSes) including WordPress, Joomla, PrestaShop, Magneto, Drupal, vBulletin, osCommerce, OpenCart, and Yeager since November 2019.

The botnet takes over these infected websites to mine for cryptocurrency, send spam messages and deface websites.

The KashmirBlack botnet infected the platforms by exploiting known vulnerabilities on the targeted servers that have not been updated and performs millions of attacks per day on average. CMSes can be easily exploited for their known vulnerabilities as they are usually not kept up-to-date. This reflects the importance of patching all vulnerabilities on your server and web application.

When a website using a CMS is not protected by a web application firewall, it is susceptible to similar botnet attacks. Not only does this compromise your website, but you put your website visitors at risk too.

