Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Balada Injector

67
Global rank
63 infographic chevron month
Month rank
66 infographic chevron week
Week rank

Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.

Backdoor
Type
Unknown
Origin
2 July, 2017
First seen
8 October, 2026
Last seen

How to analyze Balada Injector with ANY.RUN

Type
Unknown
Origin
2 July, 2017
First seen
8 October, 2026
Last seen

IOCs

IP addresses
142.251.127.84
188.114.97.3
57.153.246.3
150.171.109.98
150.171.22.17
150.171.27.11
35.190.80.1
192.178.183.94
142.251.153.119
142.251.110.138
95.100.158.106
2.23.246.9
172.217.114.4
2.16.168.39
150.171.28.11
23.59.18.102
142.251.110.139
142.250.154.139
135.232.92.97
142.251.14.95
Hashes
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
3dbd2c90050b652d63656481c3e5871c52261575292db77d4ea63419f187a55b
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
Domains
ogads-pa.clients6.google.com
www.bing.com
accounts.google.com
www.bicyclebusgrave.wiki
config.edge.skype.com
edge-mobile-static.azureedge.net
edge-cloud-resource-static.azureedge.net
fonts.gstatic.com
activation-v2.sls.microsoft.com
www.google.com
clientservices.googleapis.com
oneocsp.microsoft.com
edge.microsoft.com
ogs.google.com
play.google.com
update.googleapis.com
api.edgeoffer.microsoft.com
incolorand.com
fe3cr.delivery.mp.microsoft.com
copilot.microsoft.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:gi7fmngarebrgibe8zll8npgd6wxxtw20xbqyjtayys&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://pulse.aetherbyteflow3.baby/file.zip?c=alpuxmodgguan4icaelefwasaaaaaacf&s=360989
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://incolorand.com/quick-projects-with-logsaw-build-a-rustic-bench-in-a-weekend/?utm_source=alpuxmodgguan4icaelefwasaaaaaacf&utm_term=file.zip&utm_content=13&utm_medium=360989
https://incolorand.com/favicon.ico
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://a.nel.cloudflare.com/report/v4?s=hzbbwbm4g1%2b0jzxor%2fb5rfypchd8duukanti0tlyj%2fznhfaveaedgekxw6onmbmoapaqybj0yumz4zn7fdjbdqgrgowfhxtqlrzwj%2bdk8ddfmw24gluct5haq8qgn3u3ba%3d%3d
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1791426262&lafgdate=0
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://incolorand.com/quick-projects-with-logsaw-build-a-rustic-bench-in-a-weekend/?utm_term=file.zip&utm_content=13&utm_medium=360989&utm_source=q60dd0548028a0000000008066419
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://www.bascetbriliant.wiki/click?offer_id=37401&pub_id=226765&site=360847&pub_click_id=ann-xmqpgquapzacaexvfwasaaaaaac5
https://www.bicyclebusgrave.wiki/click?offer_id=37401&pub_id=226765&site=360847&pub_click_id=ann-xmqpgquapzacaexvfwasaaaaaac5
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 230
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 2820
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 4352
comments 0

What is Balada Injector?

Balada Injector is a large-scale and persistent malware campaign that has been targeting WordPress websites since 2017, potentially compromising nearly one million sites. While it was active for years, the campaign was officially named "Balada Injector" in December 2022.

This malware exploits vulnerabilities in WordPress plugins and themes, injecting malicious code and backdoors that redirect end users to fake and harmful sites. In addition to redirections, Balada Injector exfiltrates sensitive information, such as database credentials, archive files, access logs, and other data that may not be securely stored.

A notable wave of attacks occurred in September 2023 when the campaign exploited a cross-site scripting (XSS) vulnerability in CVE-2023-3169, associated with the tagDiv composer plugin. During these attacks, the malware employed injection methods such as HTML, database, and arbitrary file injections. The attackers also planted backdoors capable of executing PHP code and installed malicious WordPress plugins, including one named "wp-zexit," to maintain persistent control over compromised systems.

Balada Injector operates in recurring waves, with activity spikes observed every few weeks. Its ability to adapt and exploit newly discovered vulnerabilities, combined with techniques for maintaining long-term access, makes it a significant threat to WordPress websites globally.

Shared hosting environments, where plugins and themes may not always be securely maintained, are especially vulnerable.

The campaign's evolving methods and extensive impact highlight the need for rigorous security measures, timely updates, and proactive monitoring to protect websites from compromise.

To do this, you can use tools like ANY.RUN interactive sandbox and analyze all the suspicious activities inside a secure environment:
Analysis of Balada Injector inside ANY.RUN sandbox Analysis of Balada Injector inside ANY.RUN sandbox

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Balada Injector technical details

The main technical features and functionalities of Balada Injector include:

  • Targets known and newly discovered vulnerabilities in Wordpress plugins and themes.
  • Injects HTML, database, and arbitrary files into websites.
  • Creates backdoors capable of executing PHP code and installing malicious plugins like "wp-zexit."
  • Redirects site visitors to malicious domains, including phishing sites, fake support pages, and fraudulent giveaways.
  • Steals sensitive information such as database credentials, archive files, and access logs.
  • Operates in periodic waves, exploiting new vulnerabilities with each iteration.
  • Maintains long-term access through backdoors and malicious plugin installations.
  • Alters website code to harm SEO rankings and redirect traffic to attacker-controlled sites.
  • Evolves to leverage the latest vulnerabilities, ensuring continued effectiveness against WordPress sites.

Balada Injector execution process

To see how Balada Injector operates, let’s upload its sample into ANY.RUN’s interactive sandbox.

The infection begins with attackers exploiting known vulnerabilities, particularly in popular WordPress themes and plugins.

Once a site is compromised, the malware injects malicious scripts into various files, including critical components like 404.php. This initial payload often consists of obfuscated JavaScript that loads additional malicious scripts from attacker-controlled domains through AJAX requests.

Suricata rule triggered inside ANY.RUN sandbox by Balada Injector Suricata rule triggered inside ANY.RUN sandbox by Balada Injector

As part of this process, the malware may create new malicious admin users with randomly generated passwords, which are reported back to the attackers via POST requests. This allows the attackers to maintain control over the compromised site.

Data exfiltration is another key aspect of the Balada Injector's execution chain. The malware is designed to steal sensitive information, such as database credentials from wp-config.php files and other critical data stored on the server. Attackers often look for backup archives and logs that may contain valuable information for further exploitation.

To ensure persistent access to compromised sites, multiple backdoors are installed. This includes modifying existing files like 404.php, allowing easy access without triggering security alerts. The malware notifies attackers when a backdoor is successfully installed, enabling them to monitor their control over infected sites.

Text report of Balada Injector generated by ANY.RUN sandbox Text report of Balada Injector generated by ANY.RUN sandbox

The Balada Injector also employs a strategy of reinfection by utilizing previously collected data on compromised domains to launch subsequent attacks on these sites or related ones sharing the same server environment. If direct access methods fail, attackers may initiate brute-force attacks against admin accounts, attempting numerous credential combinations in an effort to gain access.

Evasion techniques are integral to the Balada Injector's effectiveness. The campaign frequently changes its command and control (C2) domains and employs various obfuscation techniques in its scripts to avoid detection by security software. By using newly registered domains for each wave of attacks, the malware complicates efforts to block it effectively.

Balada injector distribution methods

There are several ways that attackers use to distribute the Balada Injector malware. The most common ones include:

  • Exploitation of vulnerabilities: Balada Injector primarily spreads by exploiting known and newly discovered vulnerabilities in WordPress plugins, themes, and core components. These vulnerabilities often include cross-site scripting (XSS), SQL injections, and other flaws that allow attackers to inject malicious code.
  • Outdated WordPress components: Sites running outdated versions of WordPress, plugins, or themes are particularly vulnerable. Attackers target these unpatched systems to gain unauthorized access.
  • Shared hosting environments: In shared hosting setups, Balada Injector can exploit vulnerabilities in one site to compromise other sites hosted on the same server.
  • Injection through insecure plugins: Attackers leverage plugins with inadequate security, such as the tagDiv composer plugin (CVE-2023-3169), to plant malicious scripts or backdoors.

Gathering threat intelligence on Balada injector malware

To gather up-to-date intelligence on Balada Injector, utilize Threat Intelligence Lookup.

This tool provides access to a comprehensive database of insights derived from millions of malware analysis sessions performed in the ANY.RUN sandbox. With over 40 customizable search options, you can uncover detailed information on threats, including IPs, domains, file hashes, filenames, and process artifacts.

Balada Injector search in ANY.RUN’s TI Lookup Balada Injector search in ANY.RUN’s TI Lookup

For example, you can look up Balada Injector directly by its name or search using related artifacts. Entering a query such as threatName:"Balada" in the Threat Intelligence Lookup will display all relevant samples and sandbox results linked to this malware, providing you with actionable intelligence.

Start exploring with a 14-day free trial of Threat Intelligence Lookup and the ANY.RUN sandbox today!

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Balada Injector is a persistent threat, exploiting vulnerabilities in WordPress plugins and themes to inject malicious code, steal data, and create backdoors. Proactively analyzing suspicious activity is essential to prevent compromises and protect your site from such malware.

ANY.RUN provides real-time malware analysis, enabling users to investigate malicious activity, uncover attack methods, and gather actionable intelligence to strengthen security defenses.

Sign up for a free ANY.RUN account today and start analyzing cyber threats like Balada Injector!

HAVE A LOOK AT

Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More