A new malware (backdoor) is posing as a legitimate caching plugin and targeting WordPress sites, allowing attackers to create an account and control site activity.
The backdoor has various functions that allow it to manage plugins and hide on compromised websites, replace content , or redirect users to malicious sites.

Fake caching plugin
Analysts at Defiant, makers of the Wordfence security plugin for WordPress, discovered the new malware in July.
Taking a closer look at the backdoor, the researchers noticed that it is accompanied by a comment (which looks quite professional) and presents it as tool , which usually helps improve page load time.
See also: Balada Injector attacks: 17,000 WordPress sites compromised
The backdoor's creators have created it this way and imitate this particular tool to go unnoticed. The malicious add-on is also configured to be excluded from the list of "active plugins", which helps it avoid detection.
WordPress backdoor capabilities
User creation: One function creates a user named “superadmin” with a hard-coded password and administrator-level permissions, while a second can remove this user to erase the trace of the infection.
Bot Detection: When detecting bots (e.g. search engine crawlers), malware presents different content, such as spam content, causing them to index the compromised site for malicious content. As a result, administrators could see a sudden increase in traffic or reports from users complaining about being redirected to malicious sites.
Content replacement: Malware can change posts and content on a page and insert spam links or buttons.
Plugin Control: Malware operators can remotely enable or disable WordPress plugins on the compromised website. It also cleans its traces from the website’s database. So, this activity remains hidden.
Remote invocation: The backdoor checks for specific user agent strings, allowing attackers to remotely trigger various malicious functions.
According to the researchers, all of these features, combined, provide attackers with everything they need to control the site, affecting both the site itself and visitors.
See also: Backdoor found in budget Android TV boxes

At this time, Defiant has not provided details on the number of websites that have been compromised with the new backdoor and they have not specified how the attack is initiated.
Typical methods for hacking a website include stolen credentials, brute-forcing passwords, or exploiting a vulnerability in a plugin or theme.
Defiant has released a detection signature for users of the free version of Wordfence and added a firewall rule to protect Premium, Care, and Response users from the backdoor.
In the modern age of digital technology, cybersecurity is an increasingly challenging battlefield. Our attention is now focused on attacks against WordPress websites.
The recently discovered backdoor poses a serious risk to website owners, as attackers can access ,control and consequently destroy the content hosted on them.
See also: SprySOCKS: New Linux backdoor used in Chinese espionage campaigns
How can we protect ourselves?
Although the picture created by this risk may seem pessimistic, there are steps that can be taken to address this threat. We should not neglect the importance of system updates and installing reliable security. Also, website owners should use strong and unique credentials for administrator accounts, keep their plugins updated , and remove unused add-ons and users. Above all, being aware and careful with your actions, in this digital world, is a decisive factor for security.
Source: www.bleepingcomputer.com
