Thousands of WordPress Websites Infected with Malware
ID: c5cbf68a-bbf2-5f73-a431-003227429c3a
STIX ID: report--c5cbf68a-bbf2-5f73-a431-003227429c3a
Feed Name: Schneier on Security
Threat Score
Multiple sources report thousands of WordPress sites infected by a large campaign that injected third-party JavaScript to install four separate backdoors. The backdoors include a fake plugin installer for remote commands, JavaScript injection into wp-config.php, addition of attacker-controlled SSH keys for persistent shell access, and a component that fetches payloads to execute remote commands or open reverse shells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
