Sneaky WordPress Malware Disguised as Anti-Malware Plugin
ID: 08bf1eae-77f0-5f3a-a583-62a42f65bef8
STIX ID: report--08bf1eae-77f0-5f3a-a583-62a42f65bef8
Feed Name: HackRead
Wordfence researchers discovered a deceptive WordPress malware posing as an anti-malware plugin (e.g., WP-antymalwary-bot.php/addons.php) that grants attackers admin access via GET parameters (check_plugin, emergency_login), performs remote code execution through a REST API endpoint (execute_admin_command), hides from the admin plugin list, reports to C2 45.61.136.85, injects advertising JavaScript, and persists by modifying wp-cron.php to reinstall deleted components; discovery dated Jan 22, 2025 with signatures and firewall rules released in April/May 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
