• Download the Constitution of Pakistan
  • Advertise
Friday, December 5, 2025
  • Login
NEWSLETTER
ECONOMY
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
ECONOMY
No Result
View All Result
Home Cyber Security

WordPress Antivirus Turned Out to Be a Trojan

by Syed Mahad
May 1, 2025
in Cyber Security, Technology
Reading Time: 2 mins read
0
WordPress Antivirus
Share on FacebookShare on TwitterLinkedinWhatsapp

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP

Syed Mahad

Related Posts

Youtube AUS

YouTube Blocks Under-16 Users in Australia

by Anum Arif
December 3, 2025
0

YouTube has announced that it will block users under the age of 16 in Australia, complying with a landmark social...

Samsung Multi Fold smartphone

Samsung Launches First Multi-Fold Smartphone, Galaxy Z TriFold

by Anum Arif
December 2, 2025
0

SEOUL (Reuters) – Samsung Electronics on Tuesday unveiled its first multi-folding smartphone, the Galaxy Z TriFold, signaling the company’s push...

Netflix

Netflix Ends Casting Support on Newer Devices

by Anum Arif
December 1, 2025
0

Netflix has disabled the option to cast TV shows and movies from smartphones to most modern streaming devices, a change...

South Korea AI robot dolls

South Korea Introduces AI Robo Dolls for Seniors

by Anum Arif
November 28, 2025
0

South Korea has launched an innovative initiative to tackle loneliness among its elderly population by introducing AI-powered “robo dolls.” Designed...

Whatsapp

WhatsApp Bans Third‑Party AI Chatbots from January 2026

by Anum Arif
November 27, 2025
0

WhatsApp has announced significant changes to its terms of service, set to take effect on January 15, 2026, that will...

Lithium Deposit

Quebec Lithium Deposit Could Power 1.6 Billion EVs

by Anum Arif
November 26, 2025
0

A significant lithium deposit has been discovered in Quebec, with estimates suggesting it could produce up to 329 million metric...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Economy.pk is a source of economic, political, business, finance, health and sports updates.

Important Categories

  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

Social Media

  • Facebook
  • Instagram
  • Twitter
  • Linkedin
  • YouTube
  • Linkedin
  • TikTok
  • WhatsApp
  • About
  • Advertise
  • Careers
  • Contact

© 2024 Economy.pk - Web Development by Digital Otters

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

© 2024 Economy.pk - Web Development by Digital Otters