Malware Poses as WordPress Caching Plugin to Hijack Websites
Premium Content
to watch this episode.
A recently discovered malware is masquerading as a legitimate caching plugin for WordPress, deceiving website owners and giving cybercriminals an entry point to hijack their sites. This malicious software operates as a backdoor, offering a range of functionalities that empower it to manipulate plugins, conceal itself from active plugins on compromised websites, substitute content, or divert specific users to harmful destinations.
The experts at Defiant, the developers behind the Wordfence security plugin for WordPress, first encountered this malware in July while conducting maintenance on a website. Upon closer examination of the backdoor, it became apparent that it cleverly masked itself as a caching tool, a type of plugin known for optimizing a website’s performance by alleviating server load and enhancing page loading times.
This strategy of mimicking a legitimate tool is a deliberate move to evade manual inspections and fly under the radar. Furthermore, the malicious plugin is programmed to exclude itself from the list of “active plugins,” a crafty tactic designed to escape scrutiny.
The malware boasts an array of capabilities, including creating a user with admin-level permissions, altering content, and even controlling plugins remotely. Notably, it can take action to obscure its presence, eliminating any traces of the infection.
See Also: So you want to be a hacker?
Trending:
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: [email protected]
Source: bleepingcomputer.com
SOCIAL SHARE CARD GENERATOR