• Download the Constitution of Pakistan
  • Advertise
Sunday, February 1, 2026
  • Login
NEWSLETTER
ECONOMY
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
ECONOMY
No Result
View All Result
Home Cyber Security

WordPress Antivirus Turned Out to Be a Trojan

by Syed Mahad
01/05/2025
in Cyber Security, Technology
Reading Time: 2 mins read
0
WordPress Antivirus
Share on FacebookShare on TwitterLinkedinWhatsapp

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP

Syed Mahad

Related Posts

WhatsApp Introduces Strict Account Settings for Enhanced Security

WhatsApp Introduces Strict Account Settings for Enhanced Security

by Hassan Mustafa Bajwa
28/01/2026
0

WhatsApp has launched a new high-security feature called "Strict Account Settings" aimed at providing stronger protection against cyber threats. This...

NASA Shares Images of Helix Nebula Illustrating Solar System’s Distant Future

NASA Shares Images of Helix Nebula Illustrating Solar System’s Distant Future

by Hassan Mustafa Bajwa
26/01/2026
0

NASA has released striking images of the Helix Nebula, offering a glimpse into the distant future of our solar system....

Chinese Scientists Discover Key to Dramatically Increase Data Storage Capacity

Chinese Scientists Discover Key to Dramatically Increase Data Storage Capacity

by Hassan Mustafa Bajwa
24/01/2026
0

Chinese scientists have made a significant advancement in material science that promises to greatly increase digital data storage capabilities. Researchers...

Meta Suspends Teen Access to AI Characters Worldwide Amid Safety Updates

Meta Suspends Teen Access to AI Characters Worldwide Amid Safety Updates

by Hassan Mustafa Bajwa
24/01/2026
0

Meta Platforms has announced it will temporarily block teenagers from accessing AI characters across all its applications worldwide. This decision...

Microsoft 365 Experiences Service Disruption Affecting Thousands

Microsoft 365 Experiences Service Disruption Affecting Thousands

by Hassan Mustafa Bajwa
23/01/2026
0

Thousands of Microsoft 365 users experienced service interruptions on Thursday, as reported by outage monitoring platform Downdetector. The disruption affected...

Apple Prepares to Launch Its First Foldable iPhone

Apple Prepares to Launch Its First Foldable iPhone

by Hassan Mustafa Bajwa
23/01/2026
0

Apple is gearing up to enter the foldable smartphone market with the imminent release of its first foldable device, likely...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Economy.pk is a source of economic, political, business, finance, health and sports updates.

Important Categories

  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

Social Media

  • Facebook
  • Instagram
  • Twitter
  • Linkedin
  • YouTube
  • Linkedin
  • TikTok
  • WhatsApp
  • About
  • Advertise
  • Careers
  • Contact

© 2024 Economy.pk - Web Development by Digital Otters

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

© 2024 Economy.pk - Web Development by Digital Otters