A large-scale phishing campaign targets WordPress WooCommerce users
ID: 77986a52-ec75-57a9-add2-64d42b986888
STIX ID: report--77986a52-ec75-57a9-add2-64d42b986888
Feed Name: Security Affairs
Patchstack and SecurityAffairs report a large-scale phishing campaign targeting WordPress WooCommerce users that uses a fake security alert (spoofing a CVE and an IDN-homograph WooCommerce domain) to trick victims into downloading a malicious plugin (e.g., authbypass-update-31297-id.zip). Once installed, the plugin adds a hidden WP Cron job that creates concealed administrator accounts, contacts attacker-controlled domains to exfiltrate credentials and fetch obfuscated PHP web shells (P.A.S.-Fork, p0wny, WSO), and hides its presence; indicators include suspicious folders (wp-content/plugins/authbypass-update, wp-content/uploads/wp-cached-<8chars>), cronjob names like mergeCreator655, random 8-char admin usernames, and outbound requests to domains such as woocommerce-services.com, woocommerce-api.com, and woocommerce-help.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
