• Download the Constitution of Pakistan
  • Advertise
Saturday, December 13, 2025
  • Login
NEWSLETTER
ECONOMY
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
ECONOMY
No Result
View All Result
Home Cyber Security

WordPress Antivirus Turned Out to Be a Trojan

by Syed Mahad
May 1, 2025
in Cyber Security, Technology
Reading Time: 2 mins read
0
WordPress Antivirus
Share on FacebookShare on TwitterLinkedinWhatsapp

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP

Syed Mahad

Related Posts

Ai powered driverless car

NED University Tests Pakistan’s First AI Driverless Car

by Anum Arif
December 12, 2025
0

In a groundbreaking achievement for Pakistan’s technology sector, engineers at the NED University of Engineering and Technology have successfully completed...

EU Google

EU Probes Google Over AI Use of Publisher Content

by Anum Arif
December 10, 2025
0

The European Commission has opened a sweeping antitrust investigation into Google, focusing on whether the tech giant is using online...

Australia implements minimum age for social media use

Australia Implements Minimum Age for Social Media Use

by Anum Arif
December 9, 2025
0

From December 11, 2025, Australia will enforce a minimum age of 16 for social media use, requiring major platforms such...

Cloudfare

Cloudflare Outage Hits Major Global Platforms

by Anum Arif
December 8, 2025
0

Internet infrastructure provider Cloudflare issued an apology following a major outage on Friday morning, impacting key platforms including LinkedIn, Zoom,...

Phoenix glasses Meta

Meta Delays Phoenix MR Glasses to 2027

by Anum Arif
December 6, 2025
0

Meta has officially delayed the launch of its highly anticipated mixed reality glasses, code-named Phoenix, pushing the release from late...

Ronaldo Perplexity

Ronaldo backs Perplexity AI with CR7 digital hub.

by Anum Arif
December 5, 2025
0

Football legend Cristiano Ronaldo has entered the tech world in a major way, announcing a high-profile investment and brand partnership...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Economy.pk is a source of economic, political, business, finance, health and sports updates.

Important Categories

  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

Social Media

  • Facebook
  • Instagram
  • Twitter
  • Linkedin
  • YouTube
  • Linkedin
  • TikTok
  • WhatsApp
  • About
  • Advertise
  • Careers
  • Contact

© 2024 Economy.pk - Web Development by Digital Otters

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

© 2024 Economy.pk - Web Development by Digital Otters