GoDaddy Security Researchers have identified a surge in malware distribution through fake WordPress plugins. These plugins appear legitimate but inject JavaScript for fake browser update prompts, leveraging social engineering to compromise users. Threat actors use stolen admin credentials to install these plugins on websites,

13m read timeFrom godaddy.com
Post cover image
Table of contents
Key findingsOverviewFake WordPress pluginsPlugin codeMalicious scriptsPrevious iteration of fake ClickFix plugins - June 2024Payloads hosted in Github and BitBucketAttack log analysis - September 2024Stolen credentials distribute fake browser updatesIndicators of compromise

Sort: