logo

Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain

ID: 153b2777-7228-5eb5-8bb3-f5255119bdd0

STIX ID: report--153b2777-7228-5eb5-8bb3-f5255119bdd0

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A sophisticated ClickFix campaign implanted an ErrTraffic-style mu-plugin in WordPress sites to serve EtherHiding JavaScript that fetched payloads from BSC Testnet smart contracts and social-engineered Windows users into running a UNC-based rundll32 load that attempted to initialize GULoader; combined ANY.RUN sandbox and EDR telemetry tied the chain to specific domains and Cloudflare-backed IPs, and Elastic Defend behavioral detection terminated the process before the loader completed initialization, with IOCs and defensive lessons provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.