Evolution of the "Work from Home" Scam
ID: f5662afa-7541-5233-9cdc-f97ff2f0e7c6
STIX ID: report--f5662afa-7541-5233-9cdc-f97ff2f0e7c6
Feed Name: Zscaler Security Research Blog
Threat Score
The report documents a widespread scam campaign where attackers inject unique PHP pages into compromised WordPress sites (commonly under /wp-includes/ or /images/) to redirect victims to fake “work from home” newspaper-style landing pages; the scam uses geo-localization and spoofed site elements to appear legitimate, and thousands of sites have been affected with mixed Google Safe Browsing detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
