Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers

Cybersecurity researchers have shed light on a new campaign targeting WordPress sites that disguises the malware as a security plugin.
The plugin, which goes by the name “WP-antymalwary-bot.php,” comes with a variety of features to maintain access, hide itself from the admin dashboard, and execute remote code.
“Pinging functionality that can report back to a command-and-control (C&C) server

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Why top SOC teams are shifting to Network Detection and Response

Next Post

Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support

Related Posts
Total
0
Share