'
Breaking
May 5, 2025

WordPress sites targeted by malicious plugin disguised as security tool | usagoldmines.com


  • Wordfence researchers uncover a new piece of WordPress malware
  • Threat actors used AI to create legitimate-looking tools
  • The malware pretends to be an anti-malware product

Security researchers have discovered a piece of WordPress malware pretending to be an antimalware solution. In late April, Marko Wotschka from the Wordfence team published a new blog post detailing an “interesting WordPress malware”: it appears in the file system as a normal WordPress plugin, often with the name ‘WP-antymalwary-bot.php’.

While looking inconspicuous at first, the researchers discovered that this plugin contains several functions that allows attackers to persist on the target website, hide the plugin from the dashboard, and remotely execute code.

“Pinging functionality that can report back to a Command & Control (C&C) server is also included, as is code that helps spread malware into other directories and inject malicious JavaScript responsible for serving ads,” Wotschka explained.

Get Keeper Personal for just $1.67/month, Keeper Family for just $3.54/month, and Keeper Business for just $7/month

​Keeper is a cybersecurity platform primarily known for its password manager and digital vault, designed to help individuals, families, and businesses securely store and manage passwords, sensitive files, and other private data.

It uses zero-knowledge encryption and offers features like two-factor authentication, dark web monitoring, secure file storage, and breach alerts to protect against cyber threats.

Preferred partner (What does this mean?)View Deal

Compromised hosting accounts

Wordfence first discovered the malicious plugin during a January 2025 site cleanup, when they discovered a modified ‘wp-cron” php file.

It created and programmatically activated the malware which was also found to have been using the names “addons.php”, “wpconsole.php”, “wp-performance-booster.php”, and “scr.php”.

If the website admin deletes the plugin, wp-cron recreates and reactivates it automatically.

Wordfence couldn’t determine who the threat actors behind the attacks are, or how they managed to compromise these websites.

There were no logs to analyze, which is why the researchers speculated that the infection happened either via a compromised hosting account, or FTP credentials. They also managed to determine that the C2 server is located in Cyprus, and that a similar attack was already seen back in June 2024.

Another thing that makes this malware interesting – as Wordfence put it – is the apparent use of Generative Artificial Intelligence (AI) in code writing.

It’s not the use of AI per se that’s interesting, but rather the fact that AI helps threat actors create “more legitimate appearing malware”.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Sightful Spacetop review: Impressive AR display… until the bugs show up | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Missing ‘recent files’ app lists in Windows 10’s Start menu are back again | usagoldmines.com

Can you spot a poisoned AI chatbot? 4 tips from a Microsoft security expert | usagoldmines.com

This Snapdragon OLED 2-in-1 laptop is a steal for just $430 | usagoldmines.com

Skype is dead. Here’s how to migrate to Teams (or pick another app) | usagoldmines.com

Windows Has an Emergency Restart Option You Probably Don’t Know About David Nield | usagoldmines.com

Foldable iPhone Said to Have Two Key Advantages Joe Rossignol | usagoldmines.com

Amazon Introduces New Low $199.95 Price on Powerbeats Pro 2, Plus More Beats Discounts Mitchel Brous...

Asustor makes veiled dig at Synology's proprietary hard drive philosophy with open and unlocked stan...

NYT Strands hints and answers for Tuesday, May 6 (game #429) | usagoldmines.com

NYT Connections hints and answers for Tuesday, May 6 (game #695) | usagoldmines.com

Quordle hints and answers for Tuesday, May 6 (game #1198) | usagoldmines.com

RTX 5080 Super 24GB and 5070 Super 18GB rumored once again – and they could be keenly priced because...

AI’s infrastructure problem isn’t tariffs, it’s unused capacity | usagoldmines.com

IPv6 networking feature hit by hackers to hijack software updates | usagoldmines.com

Powering AI: the UK’s energy challenge in the age of digital transformation | usagoldmines.com

On cusp of storm season, NOAA funding cuts put hurricane forecasting at risk Chris Vagasky, The Conv...

Get this Ryzen 7 mini PC with 32GB RAM for just $300 while you can | usagoldmines.com

Meet Sdelete, the obscure Microsoft tool that wipes data for good | usagoldmines.com

This fast, foldable USB-C wall plug with 4 ports is 40% off today | usagoldmines.com

The best Kindle for kids hits its lowest price, just in time for summer | usagoldmines.com

The Out-of-Touch Adults' Guide to Kid Culture: 100 Men vs. One Gorilla Stephen Johnson | usagoldmine...

PopClip Is Like a Supercharged Right Click for Text on Mac Pranay Parab | usagoldmines.com

Apple Announces 2025 Pride Band, Watch Face, and iPhone Wallpaper Joe Rossignol | usagoldmines.com

Gmail servers hijacked by malicious PyPI packages to spread havoc - here's how to stay safe | usago...

Microsoft has fixed a bug in Windows 10 that broke part of the Start menu – and the reason why this ...

Glass out, plastic in: New fiber optic technology set to be deployed in AI data centers is both chea...

5 signs a hacker is watching you through your PC’s webcam | usagoldmines.com

Best Windows Hello webcams 2025: Add biometric login to your PC | usagoldmines.com

Best gaming laptops 2025: What to look for and highest-rated models | usagoldmines.com

Best free password managers 2025: Online security doesn’t have to cost a thing | usagoldmines.com

Is it time to upgrade, or get a whole new gaming PC? 6 questions to ask | usagoldmines.com

Is Windows antivirus software still necessary in 2025? | usagoldmines.com

Apple Working on Under-Screen Face ID for iPhone 18 Pro, Says Leaker Tim Hardwick | usagoldmines.com

SpaceX pushed “sniper” theory with the feds far more than is publicly known Eric Berger | usagoldmin...

Apple's Second Foldable iPhone Set for 2027 Launch, Claims Kuo Tim Hardwick | usagoldmines.com

Base iPhone 18 Shifting to Spring 2027 Launch, Six Months After 18 Pro Tim Hardwick | usagoldmines.c...

Been hiding from Windows 11 24H2 due to the fuss about all the bugs? There’s nowhere to run now as M...

TeleMessage, the Signal-esque app used by the Trump administration, has been hacked | usagoldmines....

The latest Galaxy Z Fold 7 and Galaxy Z Flip 7 rumors hint at an imminent launch, and a battery upgr...

Kuo: iPhone 17e Still on Apple's 2026 Roadmap Tim Hardwick | usagoldmines.com

Kuo: Apple to Launch iPhone 19 Air With Larger Display in Late 2027 Tim Hardwick | usagoldmines.com

When attack plans go mobile | usagoldmines.com

Major DJI Osmo 360 includes dozens of images of the 360-degree camera – and its manual | usagoldmin...

Get 3 Years of Privacy with 90% off iProVPN | usagoldmines.com

Percy Jackson and the Olympians season 2: everything we know so far about the hit Disney+ show’s ret...

Co-op crisis deepens as it admits UK customer data stolen in cyberattack - up to 20 million people p...

Lenovo Legion Pro 7i 16 Gen 10 review: The new king of gaming laptops | usagoldmines.com

I saw how an “evil” AI chatbot finds vulnerabilities. It’s as scary as you think | usagoldmines.com

USB flash drives are going extinct. Use these faster alternatives instead | usagoldmines.com

iStorage launches 26TB hardware encrypted desktop hard drive; just make sure you remember your PIN a...

How to defend your cloud environments: 7 major rules | usagoldmines.com

The Last of Us takes Dina and Ellie on a tense, pictuesque Seattle getaway Kyle Orland | usagoldmine...

Lenovo's rival to Apple's Mac Studio gets one of Intel's fastest CPUs and a dedicated GeForce RTX 50...

After cheap 5K monitors, JapanNext just launched an almost-square monitor with more than 7 million p...

10 Lego cars just raced the F1 Miami Grand Prix track – here's how they were built hamish.hector@fut...

Review: Thunderbolts* is a refreshing return to peak Marvel form Jennifer Ouellette | usagoldmines.c...

Lenovo unleashes its most powerful mobile workstation but the ThinkPad P16s won't beat HP's ZBook Ul...

Global bean counters are struggling to find value for money in anything AI and that is a big, big pr...

Huge iPhone 17 Air news teased in new report – 3 things you need to know | usagoldmines.com

Largest bank in the world issues stark security warning about technology that billions use every sin...

Amazon Takes $100 Off iPad Mini 7 With Return of All-Time Low Prices, Starting at $399 Mitchel Brous...

Quordle hints and answers for Monday, May 5 (game #1197) | usagoldmines.com

NYT Strands hints and answers for Monday, May 5 (game #428) | usagoldmines.com

NYT Connections hints and answers for Monday, May 5 (game #694) | usagoldmines.com

You need to be careful when buying new vinyl – the digital music loudness war can mean they sound wo...

What is WordPress hosting? | usagoldmines.com

iPhone release date schedule could be set for a big shakeup – here's what we know | usagoldmines.co...

I tested two mid-range Dolby Atmos soundbars side-by-side, and the battle for your money has never b...

The Roku Channel is free, and you don’t need a Roku device to watch | usagoldmines.com

No, this is not the PS5 gaming console, but rather a mini PC that supports a 120W GeForce RTX 5060 G...

Chips aren’t improving like they used to, and it’s killing game console price cuts Andrew Cunningham...

Apple might be blowing over a billion dollars a year but I think The Studio is worth every penny | ...

A DOGE recruiter is staffing a project to deploy AI agents across the US government Caroline Haskins...

Learn to code plus get the same tools as the pros — All for $55.97 | usagoldmines.com

Nobody Wants This season 2: everything we know so far about the hit Netflix show’s return | usagold...

Asking remote job candidates this shocking question could save your company big bucks, security expe...

Amazon Has Every M4 MacBook Air on Sale for Up to $165 Off This Weekend Mitchel Broussard | usagoldm...

A 100-lumens DVD-class DLP projector, a 64-megapixel night camera and... a camping light: that's not...

128TB SSD going mainstream as Innodisk announces its Gen5 flagship solid state drive with 14GBps rea...

Wi-Fi? More like Wow-Fi - researchers transmit almost 2 million Netflix HD streams simultaneously us...

iPhone 17e Looking Less Likely — Here's Why Joe Rossignol | usagoldmines.com

MacBooks are now legitimate gaming machines – and the future looks promising | usagoldmines.com

Windows 7 took ages to load if you had a solid background. Now we know why | usagoldmines.com

Apple Plans Split iPhone Launch Strategy: Pro and Foldable in Fall 2026, Standard in Spring 2027 Jul...

iPhone 18 Pro Models Rumored to Feature Under-Screen Face ID With Top-Left Camera Hole Joe Rossignol...

20th-Anniversary iPhone Will Reportedly Feature an All-Screen Design Joe Rossignol | usagoldmines.co...

The latest Sony WH-1000XM6 leaks may have revealed the design and pricing of the headphones | usago...

RIP the DJI Phantom, the drone that started it all – and got me into aerial photography | usagoldmi...

iPhone 17 Air Expected to Have Battery Case Due to 'Worse' Battery Life Joe Rossignol | usagoldmines...

Businesses globally are set to lose $15 billion in 2025 because of fraudulent chargebacks, says Mast...

AirPods Pro 2 Available for Lowest Price of the Year so Far at $169, Plus AirPods 4 at $99 Mitchel B...

NYT Strands hints and answers for Sunday, May 4 (game #427) | usagoldmines.com

Quordle hints and answers for Sunday, May 4 (game #1196) | usagoldmines.com

NYT Connections hints and answers for Sunday, May 4 (game #693) | usagoldmines.com

Top Stories: Epic Games Victory Over Apple, iPhone 17 Rumors, and More MacRumors Staff | usagoldmine...

After Thunderbolts*, Marvel has the perfect opportunity to do the unthinkable with The Fantastic Fou...

We just got another big hint that the Samsung Galaxy S25 FE is on the way | usagoldmines.com

700 projectors assembled at an art exhibition to create the world's largest digital art experience: ...

Leave a Reply