• AED to PKR – Convert UAE Dirhams to Pakistani Rupees
  • CAD to PKR – Convert Canadian Dollars to Pakistani Rupees
  • Economy.pk
  • GBP to PKR – Convert British Pounds to Pakistani Rupees
  • SAR to PKR – Convert Saudi Riyals to Pakistani Rupees
  • USD to PKR – Convert US Dollars to Pakistani Rupees
Sunday, April 12, 2026
  • Login
No Result
View All Result
Economy.pk
  • Business
  • Economy
  • Technology
  • Sports
  • Education
  • Health
  • Politics
  • World
  • Gold Rates
  • Business
  • Economy
  • Technology
  • Sports
  • Education
  • Health
  • Politics
  • World
  • Gold Rates
No Result
View All Result
Economy.pk
No Result
View All Result

WordPress Antivirus Turned Out to Be a Trojan

by Web Desk
May 1, 2025
in Cyber Security, Technology
0
WordPress Antivirus
46
SHARES
4.6k
VIEWS
Share on FacebookX

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP
Web Desk

Web Desk

Related Posts

Top 10 EV Companies in Pakistan & Their Electric Bikes (2026 Guide)

Top 10 EV Companies in Pakistan & Their Electric Bikes (2026 Guide)

by Web Desk
April 3, 2026
0

Electric vehicles (EVs) are rapidly gaining momentum in Pakistan as fuel prices continue to rise and environmental awareness grows. The...

Govt committed to facilitating global investors, especially in IT sector: PM

Govt committed to facilitating global investors, especially in IT sector: PM

by Web Desk
April 1, 2026
0

Prime Minister Shehbaz Sharif has reiterated the government’s commitment to facilitating international investors, particularly in the Information Technology sector, as...

MARI energies announces oil, gas discovery in Ghotki

MARI energies announces oil, gas discovery in Ghotki

by Web Desk
March 19, 2026
0

Mari Energies Limited on Thursday announced a significant gas and condensate discovery at its Shams-1 exploratory well, located in the...

Online Earning in Pakistan 2026 – Complete Guide for Beginners

Online Earning in Pakistan 2026 – Complete Guide for Beginners

by Web Desk
March 17, 2026
0

With the rapid growth of digital platforms, online earning in Pakistan in 2026 has become easier and more accessible than...

Economy.pk.jpg

The Economics of Everyday Tech: Why Affordable Accessories Matter in Pakistan’s Consumer Market

by Web Desk
March 15, 2026
0

Every Pakistani with a smartphone, tablet or laptop is aware of this frustration: you are out, the battery is dead,...

WhatsApp Introduces Strict Account Settings for Enhanced Security

WhatsApp Introduces Strict Account Settings for Enhanced Security

by Web Desk
March 15, 2026
0

WhatsApp has launched a new high-security feature called "Strict Account Settings" aimed at providing stronger protection against cyber threats. This...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Ads

  • AED to PKR – Convert UAE Dirhams to Pakistani Rupees
  • CAD to PKR – Convert Canadian Dollars to Pakistani Rupees
  • Economy.pk
  • GBP to PKR – Convert British Pounds to Pakistani Rupees
  • SAR to PKR – Convert Saudi Riyals to Pakistani Rupees
  • USD to PKR – Convert US Dollars to Pakistani Rupees

© 2026 All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Economy
  • Technology
  • Sports
  • Education
  • Health
  • Politics
  • World
  • Gold Rates

© 2026 All Rights Reserved

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.