Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new malware campaign targeting WordPress websites has been discovered by Sucuri last month. The malware employs a PHP-based backdoor to deploy a Windows Trojan. The infection chain is stealthy and multi-layered, making detection challenging. It utilises obfuscated code and IP-based evasion techniques. To ensure persistence, the malware adds a registry entry on the compromised system.
Impact
The potential impact of this campaign on affected organisations is significant, with risks including sensitive data theft, operational disruptions, and reputational damage. The targeted sectors, particularly energy and critical infrastructure, are vital for national security, making the implications of such attacks far-reaching. Organisations may face financial losses due to downtime and recovery efforts, alongside potential regulatory repercussions.
Exploitation
Cybercriminals use various methods to spread malware. These include phishing emails with malicious links or attachments, malicious websites that automatically download malware, and exploiting vulnerabilities in outdated software. They may also bundle malware with legitimate software or distribute fake updates. Social engineering techniques, like impersonation, trick individuals into compromising security.
Indicators of Compromise
The table below lists the indicators of compromise (IoC) for the latest WordPress malware campaign.
| IoC Type | IoC Value | Description |
| File | count.txt | A log file used to store visiting IPs |
| File | header.php | The main malicious controller |
| File | man.php | A disguised file interaction handler |
| File | psps.zip | A fake ZIP archive containing client32.exe, a Windows Trojan |
| File | update.bat | A generated batch file that downloads and executes malware |
Containment, Mitigations & Remediations
Mitigating malware involves several strategies. Organisations should use security software and keep all software up to date to patch vulnerabilities. Employee training on phishing and social engineering attacks is crucial. Network segmentation can limit the spread of malware, while regular backups ensure data can be restored. Implementing strong authentication, such as multi-factor authentication, adds an extra layer of security.
Threat Landscape
The discovery of this stealthy WordPress malware campaign underscores the evolving nature of cyber threats targeting web platforms. As threat actors continue to refine their techniques, it is imperative for website owners to remain vigilant and proactive in their security measures. By implementing robust security practices and staying informed about emerging threats, the risk of infection can be significantly reduced.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information
Stealthy WordPress Malware Drops Windows Trojan via PHP Backdoor













