logo

Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers

ID: ae023e21-db12-586d-bdc6-70a9c82a4903

STIX ID: report--ae023e21-db12-586d-bdc6-70a9c82a4903

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-05-01

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Wpeeper is a newly reported Android backdoor distributed via a trojanized Uptodown app (package com.uptodown) that embeds an ELF binary to provide backdoor capabilities: device and file information collection, file upload/download, command execution, and self-delete. The campaign used a multi-tier C2 architecture that leverages compromised WordPress sites as HTTPS-based relays to obscure true C2 servers (45 C2s identified, nine hard-coded redirectors), had limited but measurable distribution (~2,609 downloads of the trojanized app), and was observed briefly in April 2024 before ending.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.