WordPress plugin disguised as a security tool injects backdoor
ID: 589e0bf1-df8c-5601-8dae-a4c77f439b33
STIX ID: report--589e0bf1-df8c-5601-8dae-a4c77f439b33
Feed Name: Bleeping Computer
Wordfence discovered a WordPress malware campaign that uses a modified wp-cron.php to create and auto-activate hidden malicious plugins (examples: WP-antymalwary-bot.php, addons.php, wpconsole.php, wp-performance-booster.php, scr.php). The plugin provides immediate administrator access via an emergency_login backdoor, exposes an unauthenticated REST API to insert PHP into theme header.php files and clear caches, and can inject base64-decoded JavaScript into pages; it persists by re-creating deleted plugins on next site visit and likely spreads via compromised hosting or FTP credentials. Indicators include modified wp-cron.php and header.php, plugin filenames, and access log strings like "emergency_login", "check_plugin", "urlchange", and "key"; the campaign's C2 was observed in Cyprus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
