Sign1 is a website-injection malware campaign affecting WordPress sites. The provided content states that it infected more than 39,000 websites over a six-month period. Sign1 is used to inject malicious JavaScript into compromised sites, including via custom HTML widgets and legitimate plugins, causing visitor redirections and pop-up advertisements. It is discussed alongside other website injection campaigns such as Balada and DollyWay.
The content links Sign1-associated compromises to the broader VexTrio malicious traffic distribution ecosystem. Compromised WordPress sites injected with Sign1 have been used to redirect victims through VexTrio infrastructure and, after disruption of Los Pollos/VexTrio push monetization in November 2024, to Help TDS. The reporting also notes examples of injections using DNS TXT record-based mechanisms in the same ecosystem, though the content does not explicitly state that Sign1 itself uses that technique. High-confidence targeting is WordPress websites and their visitors; the observed impact on visitors includes redirects to scam or advertising content and pop-up ads. No specific file hashes, domains, or other Sign1-specific IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content lists prior/related publications including: “Sign1 Malware: Analysis, Campaign Highlights, and Indicators of Compromise”.
Sign1 is a website malware strain that injects code into WordPress sites to redirect visitors to malicious TDSs such as VexTrio. It is part of a broader set of injection campaigns exploiting WordPress vulnerabilities for monetization via malicious adtech.
Sign1 is a malicious script injected into websites to facilitate redirection to scam and malware infrastructure operated by TDS networks like VexTrio.
Malicious JavaScript campaign infecting WordPress sites via injected widgets/plugins to force redirects and pop-up ads (ad-injection).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.