WordPress plugin disguised as a security tool injects backdoor

WordPress plugin disguised as a security tool injects backdoor
Summary: A new malware campaign is targeting WordPress sites using a malicious plugin masquerading as a security tool to gain unauthorized access. This malware facilitates persistent access and remote code execution while remaining undetected in the plugin dashboard. Wordfence researchers discovered the malware during a site cleanup, revealing its ability to regenerate itself and attack via compromised credentials.

Affected: WordPress sites

Keypoints :

  • The malware creates a deceptive plugin named ‘WP-antymalwary-bot.php’ and hides itself from the plugin dashboard.
  • Attackers gain administrator access through the plugin’s features, allowing them to execute arbitrary code and manipulate site files.
  • Site owners are advised to monitor their ‘wp-cron.php’ and ‘header.php’ files for any unauthorized modifications as indicators of infection.

Source: https://www.bleepingcomputer.com/news/security/wordpress-plugin-disguised-as-a-security-tool-injects-backdoor/