• Download the Constitution of Pakistan
  • Advertise
Tuesday, June 24, 2025
  • Login
NEWSLETTER
ECONOMY
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology
No Result
View All Result
ECONOMY
No Result
View All Result
Home Cyber Security

WordPress Antivirus Turned Out to Be a Trojan

by Syed Mahad
May 1, 2025
in Cyber Security, Technology
Reading Time: 2 mins read
0
WordPress Antivirus
Share on FacebookShare on TwitterLinkedinWhatsapp

Cybercriminals are getting more creative, especially when it comes to attacking WordPress. One of the most deceptive tactics involves disguising malware as a legitimate plugin. But this recent case, uncovered by the Wordfence team, took that tactic to a whole new level.

A fake plugin named “WP-antymalwary-bot.php” infiltrated sites as a simple PHP file. Once installed, it immediately vanished from the admin panel—completely invisible to site owners. Despite its quiet appearance, the plugin packed a dangerous toolkit: remote code execution, login bypass, JavaScript injection, theme file tampering, and even a self-repairing function. Delete it? No problem—it would reinstall itself the next time someone visited the site, thanks to a compromised wp-cron.php file.

Even more disturbing was the presence of an “emergency login” backdoor. With a single GET request and a known password, hackers could hijack the first admin account available—silent but not entirely clean, as traces lingered in the logs and eventually tipped off researchers.

How the Malicious WordPress Code Operated

The infection chain began with wp-cron.php, which the malware exploited to grow its influence. It injected arbitrary PHP code into every theme’s header.php, cleared caches, and maintained regular contact with its command and control server at 45.61.136.85. This connection enabled attackers to track and potentially control a network of infected sites in real time.

The malware evolved quickly. It used WordPress’ built-in scheduler to exchange data with its C2 server at set intervals. Worse yet, it harvested malicious JavaScript from other compromised sites and embedded it directly into HTML pages, spreading infection while staying under the radar.

Experts were especially surprised by how clean and well-organized the code was. It had proper formatting, clear descriptions, and looked almost like a real, legitimate plugin—not something slapped together. This kind of polished style has been seen before, especially in attacks using AI-generated code. The new plugin shared similar traits, like unfinished features and the ability to grow more powerful over time.

The malicious code showed up under different names, such as “addons.php”, “wpconsole.php”, “scr.php”, and “wp-performance-booster.php”. You can spot it by checking for changes in “wp-cron.php”, looking for the “emergency_login” parameter in logs, or noticing edits in theme files. Learn more about cybersecurity updates here.

Tags: AntivirusCMSCybersecurityPHPTrojanWebsite DevelopmentWordPressWP
Syed Mahad

Syed Mahad

Related Posts

What is Artificial Intelligence and How AI is Everywhere Around Us?

What is Artificial Intelligence and How AI is Everywhere Around Us?

by News Publishing
June 6, 2025
0

Artificial Intelligence (AI) could be described as one of the finest innovations of the 21st century. It has become an...

Microsoft and Elon Musk

Microsoft Hosts Elon Musk’s Grok Chatbot on Azure

by Anum Arif
May 20, 2025
0

Microsoft has officially partnered with Elon Musk’s AI startup, xAI, to host the controversial chatbot Grok on its Azure cloud...

Apple iphone all glass

Apple Plans Bezel-Free Glass iPhone for 2027

by Anum Arif
May 15, 2025
0

As Apple prepares to celebrate the 20th anniversary of the iPhone in 2027, the tech giant is reportedly planning a...

Agriculture sector being developed on modern lines: PM

Agriculture sector being developed on modern lines: PM

by News Publishing
May 15, 2025
0

Prime Minister Muhammad Shehbaz Sharif has said agriculture sector is being developed on modern lines to achieve agricultural self-reliance. He...

iphone 18

Apple iPhone 18 Pro to Get Under-Display Face ID

by Anum Arif
May 14, 2025
0

California – 14 May 2025:Apple is reportedly preparing a major redesign for its 2026 iPhone 18 Pro lineup, with plans...

Samsung S25

Samsung Unveils Slimmest S25 Edge Ahead of Apple’s iPhone

by Anum Arif
May 13, 2025
0

Samsung Electronics has officially launched its slimmest flagship smartphone to date, the S25 Edge, marking a strategic move to solidify...

Next Post
M&S Suffers Digital Collapse due to Unknown Technical Issue

M&S: IT Outage Casued Digital Collapse

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

About Us

Economy.pk is a source of economic, political, business, finance, health and sports updates.

Important Categories

  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

Social Media

  • Facebook
  • Instagram
  • Twitter
  • Linkedin
  • YouTube
  • Linkedin
  • TikTok
  • WhatsApp
  • About
  • Advertise
  • Careers
  • Contact

© 2024 Economy.pk - Web Development by Digital Otters

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Business
  • Education
  • Entertainment
  • Finance
  • Health
  • Life & Style
  • Politics
  • Sports
  • Technology

© 2024 Economy.pk - Web Development by Digital Otters