WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
ID: 4ffa9fd2-3d13-536a-baff-570b807fa9ad
STIX ID: report--4ffa9fd2-3d13-536a-baff-570b807fa9ad
Feed Name: Bleeping Computer
Threat Score
Researchers at c/side discovered a malware campaign leveraging the wp3.xyz domain that has compromised more than 5,000 WordPress sites by creating a hard-coded rogue admin account (wpx_admin), installing and activating a malicious plugin (plugin.php), and exfiltrating administrator credentials and logs via obfuscated requests that mimic image traffic; site owners are advised to block wp3.xyz, review privileges and plugins, strengthen CSRF protections, and implement MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
