Balada Injector is a long-running mass-compromise malware campaign targeting WordPress websites. Active since at least 2017, it has been associated with large-scale infections affecting thousands of sites in individual waves and more than one million WordPress sites overall. The operation commonly exploits vulnerabilities in WordPress components, including cross-site scripting flaws in plugins such as Popup Builder, to inject malicious JavaScript into legitimate sites and establish server-side backdoors.
Once deployed, Balada Injector modifies compromised WordPress content and execution flow so attacker-controlled code runs in visitors’ browsers. Observed behavior includes abuse of plugin event handlers to trigger injected JavaScript and installation of a PHP backdoor on the server. The malware is primarily used to redirect visitors from legitimate websites to scam pages, fake technical-support content, and other compromised or malicious destinations. It has also been observed in broader website-compromise ecosystems where inherited malicious domains and traffic-redirect infrastructure remain embedded in hacked sites after the original operators lose control of domains.
Balada Injector is best characterized as web-focused malware used in opportunistic mass exploitation of vulnerable WordPress installations. Its core functionality centers on unauthorized code injection, persistence through backdoors, and downstream traffic monetization or victim redirection. The campaign has been repeatedly linked to exploitation of known WordPress vulnerabilities and compromises of public-facing websites rather than endpoint-focused intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Nearly 200K WordPress sites could be vulnerable to the attack thanks to CVE-2023-6000, lurking in the PopUp Builder plug-in... About 6,700 WordPress websites have been infected with the Balada Injector malware, after using a Popup Builder plug-in with a cross-site scripting (XSS) vulnerability tracked as CVE-2023-6000. | About 6,700 WordPress websites have been infected with the Balada Injector malware... The Balada Injector campaign is long-running (since 2017) ... In the attack, a backdoor is injected to redirect visitors from a legitimate WordPress site to fake support pages and compromised or scam websites.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actors in the most recent wave of activity exploited the XSS vulnerability to take over Popup Builder's "sgpbWillOpen" event and clear the way for malicious JavaScript code injection after the launch of a popup. | About 6,700 WordPress websites have been infected with the Balada Injector malware, after using a Popup Builder plug-in with a cross-site scripting (XSS) vulnerability tracked as CVE-2023-6000.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as the prior malicious association of an expired domain later acquired through dropcatch.
Mass WordPress compromise/injector malware that affected one Sable Squirrel site in a separate incident; not part of Sable Squirrel's primary malware operation.
A web-injection campaign targeting WordPress sites (via XSS in plugins) to inject obfuscated JavaScript that calls out to attacker infrastructure to fetch additional payloads and ultimately install a PHP-based backdoor for persistent access.
Malware referred to as exploiting WordPress vulnerabilities to gain unauthorized access (initial access) into networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.