Target Industry

Indiscriminate, opportunistic targeting. 

Overview

A new malware campaign targeting WordPress websites has been discovered by Sucuri last month. The malware employs a PHP-based backdoor to deploy a Windows Trojan. The infection chain is stealthy and multi-layered, making detection challenging. It utilises obfuscated code and IP-based evasion techniques. To ensure persistence, the malware adds a registry entry on the compromised system. 

Impact

The potential impact of this campaign on affected organisations is significant, with risks including sensitive data theft, operational disruptions, and reputational damage. The targeted sectors, particularly energy and critical infrastructure, are vital for national security, making the implications of such attacks far-reaching. Organisations may face financial losses due to downtime and recovery efforts, alongside potential regulatory repercussions.

Exploitation

Cybercriminals use various methods to spread malware. These include phishing emails with malicious links or attachments, malicious websites that automatically download malware, and exploiting vulnerabilities in outdated software. They may also bundle malware with legitimate software or distribute fake updates. Social engineering techniques, like impersonation, trick individuals into compromising security. 

Indicators of Compromise

The table below lists the indicators of compromise (IoC) for the latest WordPress malware campaign. 

 

IoC Type IoC Value Description 
File count.txt A log file used to store visiting IPs 
File header.php The main malicious controller 
File man.php A disguised file interaction handler 
File psps.zip A fake ZIP archive containing client32.exe, a Windows Trojan 
File update.bat A generated batch file that downloads and executes malware 

 

Containment, Mitigations & Remediations

Mitigating malware involves several strategies. Organisations should use security software and keep all software up to date to patch vulnerabilities. Employee training on phishing and social engineering attacks is crucial. Network segmentation can limit the spread of malware, while regular backups ensure data can be restored. Implementing strong authentication, such as multi-factor authentication, adds an extra layer of security. 

Threat Landscape

The discovery of this stealthy WordPress malware campaign underscores the evolving nature of cyber threats targeting web platforms. As threat actors continue to refine their techniques, it is imperative for website owners to remain vigilant and proactive in their security measures. By implementing robust security practices and staying informed about emerging threats, the risk of infection can be significantly reduced. 

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing. 

Further Information

Stealthy WordPress Malware Drops Windows Trojan via PHP Backdoor

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content