HomeSecurityWpeeper: Uses Compromised WordPress Sites to Hide C2 Servers

Wpeeper: Uses Compromised WordPress Sites to Hide C2 Servers

Cybersecurity experts have discovered a previously unknown malware, Wpeeper, which attacks Android devices using compromised WordPress.

wpeeper

This is done to conceal the real command and control servers (C2), thus making them harder to locate.

The Wpeeper malware is a binary ELF that leverages the HTTPS protocol to ensure secure communications with the command and control server (C2).

Read also: Cuttlefish Malware: Hacks routers for the purpose of secret surveillance

“Wpeeper is an advanced backdoor Trojan for Android, incorporating capabilities such as extracting sensitive device data, managing files and folders, sending and receiving data, and executing commands,” researchers from the QiAnXin XLab team report.

The ELF binary is embedded in an application that purports to be the UPtodown App Store app for Android (name “com.uptodown”), with the APK file acting as a backdoor, in a way that evades detection.

The Chinese cybersecurity company announced the discovery of malicious software, after detecting a Wpeeper program with zero detection on the VirusTotal platform on April 18, 2024. The campaign appears to have abruptly ended four days later.

The Uptodown App Store's selection for this campaign is an attempt to eliminate a legitimate third-party app market by tricking unsuspecting users into installing it. According to statistics from Android-apk.org, the version of the app containing the trojan (version 5.92) has already been downloaded 2,609 times so far.

Wpeeper is built based on the C2 tactic, where infected WordPress sites are used as proxies to hide their real C2 servers. Up to 45 C2 servers have been identified in its infrastructure, nine of which are programmed into the samples and are used for the immediate updating of the C2 list.

"These [hardcoded servers] do not function as main C2s but as C2 intermediaries. Their role is to act as relays, forwarding bot requests to the real C2, with the ultimate goal of protecting it from possible detection," the researchers said.

This has increased the likelihood that some servers with strong code will be directly put under their control, providing a high chance of losing access to the botnet if WordPress administrators discover the breach and act to fix it.

The commands received from the C2 server enable the malware to collect data from devices and files, retrieve lists of installed applications, send updates back to the C2 server, download and run new additional payloads originating from the same server or from any URL, and finally, self-destruct.

android malware

See also: New Latrodectus malware attacks exploit Microsoft themes

The precise targets and scope of this campaign remain unclear, but there is suspicion that a deceptive tactic may have been used to artificially inflate installation numbers, subsequently revealing the malicious capabilities of the malware.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

To reduce the risks of using malware, it is recommended to install applications only from trusted sources. It is also important to evaluate reviews and verify app permissions before downloading them.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS