logo

Malware exploiting XML-RPC vulnerability in WordPress

ID: d75e179a-d619-5f40-adeb-35f7cf087292

STIX ID: report--d75e179a-d619-5f40-adeb-35f7cf087292

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Win32.Backdoor.WPbrutebot**: Zscaler ThreatLabZ describes a malware campaign that enumerates and brute-forces WordPress sites via the XML-RPC wp.getUsersBlogs method, uses XOR-obfuscated strings and blockchain DNS to reach C2 servers, downloads updated backdoor payloads, and performs actions including credential access and process manipulation; the report includes analysis artifacts, MITRE TTP mappings, and IOCs (file hashes and IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.