Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » WordPress fake security plugin enables remote administrator access for attackers
Celebrities

WordPress fake security plugin enables remote administrator access for attackers

By May 1, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 1, 2025Ravi LakshmananMalware/Web Skimming

WordPress fake security plugin

Cybersecurity researchers are shedding light on a new campaign targeting WordPress sites that disguise malware as security plugins.

The plugin named “WP-Antymalwary-bot.php” comes with a variety of features to keep access, hide from the admin dashboard, and run remote code.

“It also includes ping functionality that allows you to report to command and control (C&C) servers, similar to the code that helps spread malware to other directories and inject malicious JavaScript responsible for serving ads,” Wordfence’s Marco Wotschka said in the report.

The malware first discovered in the site cleanup effort in late January 2025 was detected in the wild with a new variant. Some of the other names used for plugins are listed below –

addons.php wpconsole.php wp-performance-booster.php scr.php

Once installed and activated, it provides administrator access for threat actors to the dashboard and makes remote code execution easier by injecting malicious PHP code into site theme header files, or clearing caches for popular cache plugins.

Cybersecurity

New iterations of malware include notable changes to the manners in which code injections are handled, fetching JavaScript code hosted in another compromised domain to provide ads or spam.

The plugin is also complemented by a malicious WP-Cron.php file that automatically reproduces and reproduces malware on the next site visit if it is removed from the plugin directory.

Currently, it is not clear how the site is violated to deliver malware or who is behind the campaign. However, the presence of Russian comments and messages probably indicates that threat actors speak Russian.

This disclosure has now detailed a web skimmer campaign that uses a fake font domain named italicfonts.[.]org “Displays fake payment forms on the checkout page, steals the information entered, and removes data to the attacker’s server.

Another “advanced multi-stage carding attack” considered by the website security company targets the Magento e-commerce portal with JavaScript malware designed to harvest a wide range of sensitive information.

“The malware leveraged fake GIF image files, local browser SessionStorage data, and used malicious reverse proxy servers to tamper with website traffic and promoted credit card data, login details, cookies and other sensitive data from websites that compromise credit card data, log-in details, cookies and other sensitive data.”

A GIF file is actually a PHP script that acts as a reverse proxy by capturing incoming requests and collecting the information needed when a site visitor lands on a checkout page.

It has been observed that enemy injects Google AdSense code into at least 17 WordPress sites in various locations with the goal of delivering unwanted ads and generating revenue either on a click-by-click or impressive basis.

“They are trying to continue using resources on your site to serve ads, but even worse, if you use AdSense yourself, you may be stealing the revenue from your ads,” says security researcher Puja Srivastava. “By injecting your own Google AdSense code, they’ll be paid for you.”

Cybersecurity

That’s not all. The verification of deceit capt provided on compromised websites is designed to allow users to tunnel malicious traffic through the socks5 proxy by collecting system information, granting remote access, and tricking down node.js-based backdoor downloading and running node.js-based backdoors that deploy remote access.

This activity is attributed to a traffic distribution system (TDS), called Kongtuke (aka 404 TDS, Chaya_002, Landupdate808, and TAG-124) by TrustWave SpiderLabs.

“The JS scripts dropped after infection are designed as multifunctional backdoors that can maintain detailed system reconnaissance, remote command execution, tunnel network traffic (Socks5 proxy), and permanent access to secrets.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMavryk secures $300 million deals with MAG and Multibank in its biggest real estate RWA tokenization to date
Next Article Thai prosecutors say they will not pursue a royal defamation case against American scholars

Related Posts

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Zendaya & Tom Holland’s ‘Spider-Man’ Press Tour Couple Style

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Vote for Sombre, Phoebe Bridgers and more

Bettina Anderson reveals the designer of her wedding dress

Trending Posts

Vote for Sombre, Phoebe Bridgers and more

June 26, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.