logo

Threat Actors Hide Malware in WordPress Sites to Execute Remote Code

ID: d0e17707-860c-5b2a-9447-3bab40065bbf

STIX ID: report--d0e17707-860c-5b2a-9447-3bab40065bbf

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

**Executive Summary:** Security researchers uncovered a WordPress-targeted malware campaign that abuses the mu-plugins directory to persistently load three payloads — a fake-update redirector (wp-content/mu-plugins/redirect.php), a remote code execution webshell (wp-content/mu-plugins/index.php), and a spam injector (wp-content/mu-plugins/custom-js-loader.php) — resulting in visitor redirection to malicious sites, full site compromise, and reputational damage; recommended defenses include regular file scans, timely updates, 2FA for admins, and file integrity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.