WooCommerce admins targeted by fake security patches that hijack sites
ID: d86f2e56-148f-5aa8-bc63-8951a888bb78
STIX ID: report--d86f2e56-148f-5aa8-bc63-8951a888bb78
Feed Name: Bleeping Computer
A large-scale phishing campaign is impersonating WooCommerce and sending fake 'critical patch' alerts that lead victims to a homograph domain; installing the provided plugin creates hidden admin accounts, persistent cronjobs, and deploys PHP web shells (P.A.S.-Form, p0wny, WSO) allowing full site control, data theft, ad injection, DDoS participation or ransomware; Patchstack observed the operation and published indicators (malicious domains, plugin name, cronjob patterns and upload paths) and remediation suggestions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
