Cybersecurity researchers have uncovered a malicious campaign targeting WordPress sites using a fake security plugin, `WP-antymalwary-bot.php`, which grants attackers admin access and enables stealth reinfection and JavaScript ad fraud. The plugin camouflages itself while pinging to a command-and-control server, spreading

4m read timeFrom thehackernews.com
Post cover image
1 Comment

Sort: