Advanced Malware Campaign Targets WordPress and WooCommerce Sites with Hidden Skimmers

Advanced Malware Campaign Targets WordPress and WooCommerce Sites with Hidden Skimmers

The Wordfence Threat Intelligence Team uncovered an advanced malware campaign targeting WordPress and WooCommerce sites, with over 20 variants focused on credit card skimming and credential theft. This campaign employs sophisticated obfuscation, live backend systems disguised as rogue plugins, and real-time data exfiltration methods, posing significant risks to the web ecosystem. #Wordfence #WordPressCore

Keypoints

  • The malware campaign dates back to September 2023 and includes over 20 distinct samples.
  • Variants focus on credit card skimming, credential theft, and malicious ad manipulation.
  • Advanced techniques include embedding live backend systems and disguising malicious code as plugins.
  • Malware evades detection using obfuscation, developer tools detection, and anti-debugging methods.
  • Detection signatures have been released, with over 99% effectiveness in identifying known samples.

Read More: https://gbhackers.com/advanced-malware-campaign-targets-wordpress-and-woocommerce-sites/