A Russian malware called SoakSoak has infected over 100,000 WordPress sites since Sunday, December 14th, turning blogs into attack platforms. The malware attempts to install dangerous programs on your computer that could possibly steal or delete your information. In an attempt to curb the damage, more than 11,000 websites have been blacklisted by Google after they were found infected. According to security firm Sucuri, which is the first security firm that reported on the blacklisting, the malware uses a vulnerability in a slideshow plug-in called Slider Revolution. The Slider Revolution team have already fixed it with updates. Unfortunately, the problem is that the old, vulnerable version of the plug-in is still bundled with WordPress themes, so lots of sites are still using the wrong version. SoakSoak modifies a file in infected sites’ WordPress installation, then it loads a JavaScript malware from the soaksoak.ru domain, which is where the malware’s name comes from.