A sophisticated malware campaign targeting WordPress websitesuses advanced steganography techniques and backdoor mechanisms to maintain unauthorized administrator access.

The malware operates through two main components that work together to create a resilient attack infrastructure, allowing cybercriminals to establish persistent bases on compromised websites while remaining invisible to traditional security measures.
The attack begins by deploying malicious files that pretend to be legitimate WordPress components. These files use multiple layers of obfuscation and encryption to evade detection, creating administrator accounts with hardcoded credentials that attackers can use to maintain access even after the initial security breaches are discovered.
The malware's architecture shows a sophisticated understanding of WordPress's internal mechanisms, exploiting both the plugin infrastructure and core user management functions.
See also: Microsoft: New variant of XCSSET macOS malware
Beyond simple account creation, the malware implements advanced communication protocols with command-and-control servers, automatically transmitting compromised credentials and system information to control points controlled by the attackers. This allows threat actors to harvest administrator access credentials on multiple compromised websites simultaneously, creating extensive networks of compromised WordPress installations.

Sucuri analysts detected the malware during routine security cleanups and observed sophisticated persistence mechanisms that actively resist removal attempts. The malware’s impact extends beyond simple unauthorized access , potentially allowing attackers to inject malicious content, redirect visitors to fraudulent websites, collect sensitive information, or deploy additional malicious payloads .
The combination of concealment tactics and persistence mechanisms makes this campaign particularly dangerous for website owners who may remain unsuspecting of the breach for extended periods. The attackers maintain a silent presence on their systems.
See also: North Korean hackers use new AkdoorTea backdoor
WordPress Targeting: Advanced Persistence and Hiding Mechanisms
The malware demonstrates extreme sophistication in its persistence tactics, using a two-file approach that ensures redundant access pathways. The main component is disguised as the “DebugMaster Pro” add-on, with convincing metadata that includes version numbers, GitHub repositories, and professional descriptions. However, beneath this mask lies heavily obfuscated code designed to create administrator accounts and establish communication channels with external servers.
The malware employs multiple techniques to evade detection by both automated security tools and manual inspection. It actively removes itself from WordPress plugin lists using filtered queries and hides administrator accounts from standard user management interfaces.
See also: New LockBit 5.0 ransomware targets Windows, Linux and ESXi

The code uses extensive hexadecimal encoding and goto statements to hide its true functionality, making static analysis significantly more difficult for security researchers. In addition, the malware incorporates monitoring mechanisms IP to detect administrator access patterns while also allowing whitelisting of known administrator IP addresses to avoid exposing the malicious functionality to legitimate users.
This selective visibility ensures that the malware remains hidden from website owners while continuing to operate against normal visitors, demonstrating a sophisticated understanding of operational security typically associated with APT hacking groups.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
