logo

Cyble Sensors Detect WordPress Plugin Attack, New Trojan

ID: 5ec049ba-2dbc-56c3-a0c1-d4bbf8c7ef0a

STIX ID: report--5ec049ba-2dbc-56c3-a0c1-d4bbf8c7ef0a

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2024-10-21

Date Updated: 2026-07-17

...
...

Cyble's Threat Hunting Honeypot sensors detected active exploitation of multiple critical vulnerabilities (including several 9.x CVEs and unauthenticated RCEs), a new Octo2 banking trojan variant targeting European banks with DGA and device-takeover capabilities, more than 400 scam email addresses, and thousands of brute-force attacks against common service ports; the report includes IoCs (file hashes, package names, scam emails), attacker port distributions, and remediation recommendations (patching, blocking hashes/URLs/IPs/ports, resetting credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.