Tech

WordPress sites targeted by malicious plugin disguised as security tool

Share
Share


  • Wordfence researchers uncover a new piece of WordPress malware
  • Threat actors used AI to create legitimate-looking tools
  • The malware pretends to be an anti-malware product

Security researchers have discovered a piece of WordPress malware pretending to be an antimalware solution. In late April, Marko Wotschka from the Wordfence team published a new blog post detailing an “interesting WordPress malware”: it appears in the file system as a normal WordPress plugin, often with the name ‘WP-antymalwary-bot.php’.

While looking inconspicuous at first, the researchers discovered that this plugin contains several functions that allows attackers to persist on the target website, hide the plugin from the dashboard, and remotely execute code.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Tuxedo InfinityBook Pro 14 Gen10 is a sleek Linux laptop with serious performance
Tech

Tuxedo InfinityBook Pro 14 Gen10 is a sleek Linux laptop with serious performance

Tuxedo InfinityBook Pro 14 Gen10 sets a new bar for Linux power...

Your Nintendo Switch 2 probably wants this case as much as I do
Tech

Your Nintendo Switch 2 probably wants this case as much as I do

I’ve finally gotten my hands on a Nintendo Switch 2, and having...

ChatGPT is crushing the AI referral game, but China’s DeepSeek has shut it out in one bold move
Tech

ChatGPT is crushing the AI referral game, but China’s DeepSeek has shut it out in one bold move

ChatGPT now leads AI referral traffic worldwide, leaving Google’s Gemini far behind...