logo

Malware campaign 'DollyWay' breached 20,000 WordPress sites

ID: 79db1d32-cee7-587f-a1cc-908631ec60eb

STIX ID: report--79db1d32-cee7-587f-a1cc-908631ec60eb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

DollyWay is a long-running (since 2016) malware campaign compromising over 20,000 WordPress sites to stealthily redirect visitors to scam landing pages via a multi-stage JavaScript Traffic Distribution System; it generates roughly 10 million fraudulent impressions per month, persists through auto-reinfection and hidden WPCode/plugin injections, and is monetized through affiliate networks, with GoDaddy publishing related IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.