• Download the Constitution of Pakistan
  • Advertise
Monday, December 22, 2025
  • Login
NEWSLETTER
ECONOMY
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
ECONOMY
No Result
View All Result
Home Cyber Security

WordPress Antivirus Turned Out to Be a Trojan

by Syed Mahad
May 1, 2025
in Cyber Security, Technology
Reading Time: 2 mins read
0
WordPress Antivirus
Share on FacebookShare on TwitterLinkedinWhatsapp

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP

Syed Mahad

Related Posts

Pak and China

Pakistan, China Strengthen Digital Ties with 24 Tech MoUs

by Anum Arif
December 22, 2025
0

ISLAMABAD (APP) – Pakistan and China have expanded their technological collaboration through the signing of 24 Memoranda of Understanding (MoUs)...

Whatsapp Scam Alert

PTA Issues Alert on Rising WhatsApp Hacking Scams

by Anum Arif
December 20, 2025
0

The Pakistan Telecommunication Authority (PTA) has issued a public advisory warning mobile users about a rise in WhatsApp hacking incidents...

UK govt cyberattacked

UK Government Confirms Cyberattack Linked to China

by Anum Arif
December 19, 2025
0

LONDON — British Trade Department Minister Chris Bryant confirmed that the UK government experienced a cyberattack in October, partially validating...

Chatgpt and apple music

ChatGPT Introduces Apple Music Integration

by Anum Arif
December 18, 2025
0

ChatGPT has introduced a dedicated integration with Apple Music, allowing users to explore music and create playlists using artificial intelligence....

OnePlus-Turbo-news

OnePlus Confirms New Turbo Smartphone Series

by Anum Arif
December 16, 2025
0

OnePlus has officially announced plans to introduce a new smartphone lineup named Turbo, putting an end to weeks of speculation...

Grain of salt size robot

Grain-of-Salt Microrobot Developed for Medical Use

by Anum Arif
December 15, 2025
0

A team of scientists from the University of Pennsylvania and the University of Michigan has developed a groundbreaking sub-millimeter robot,...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Economy.pk is a source of economic, political, business, finance, health and sports updates.

Important Categories

  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

Social Media

  • Facebook
  • Instagram
  • Twitter
  • Linkedin
  • YouTube
  • Linkedin
  • TikTok
  • WhatsApp
  • About
  • Advertise
  • Careers
  • Contact

© 2024 Economy.pk - Web Development by Digital Otters

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

© 2024 Economy.pk - Web Development by Digital Otters