A particularly sophisticated phishing campaign is in full swing, targeting WordPress website administrators using ManageWP , GoDaddy ’s remote management platform . The attack leverages deceptive results – ads in Google Search, which appear above the real results, dramatically increasing the chances of users being tricked into handing over their login details .

The incident was brought to light by Guardio Labs, whose researchers identified a phishing campaign that goes beyond simply stealing usernames and passwords. Instead, the attackers are implementing an Adversary-in-the-Middle (AiTM), allowing them to steal credentials and two-factor authentication codes in real time.
This new method demonstrates how phishing is evolving into a particularly dynamic form of cyberattack, which exploits not only human carelessness, but also the trust that users place in major search engines.
See also: New malware turns Linux systems into P2P attack networks
How does a phishing attack work?
Users searching for the term “managewp” on Google see a sponsored result that perfectly mimics the service’s legitimate link. Upon clicking, they are taken to a fake login page that is almost identical to the authentic one.
The crucial element is that this page is not a simple copy. It acts as an intermediary server between the victim and the real ManageWP platform. When the user enters their details , they are immediately forwarded to the attacker via a Telegram, who uses them to attempt a real-time login.
The victim then receives a message asking for a 2FA, believing it to be a standard verification process. The attacker then uses the code, completing access to the account.
Speed of execution is crucial, as one-time codes have a limited validity period. This shows that there is an organized and automated infrastructure behind the campaign.

Why ManageWP is an attractive target
ManageWP is one of the most popular WordPress infrastructure management platforms . It allows developers, agencies, and businesses to control dozens or even hundreds of sites from a central dashboard .
See also: MuddyWater uses Chaos ransomware for “cover”
The value of a single account is enormous. According to Guardio Labs lead researcher Nati Tal, each account can host hundreds of websites.
The ManageWP plugin is active on over 1 million WordPress sites, making the platform one of the most attractive targets for large-scale attacks.
A compromised account doesn't just mean access to a website. It can give complete control over entire customer networks, allowing for content corruption, installation of backdoors, malware distribution, or even ransomware deployment.
The infrastructure behind the campaign
Guardio researchers were able to penetrate the perpetrators' command-and-control infrastructure and observe a fully interactive phishing system.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Unlike mass phishing kits sold on underground forums, this platform appears to be a private framework, designed exclusively for targeted, high-performance attacks.
A particularly interesting finding was the presence of a Russian-language user agreement within the code. The text includes a disclaimer, a reference to “educational use,” and a prohibition on attacks against Russian infrastructure.
This specific practice has appeared repeatedly in cybercrime tools and is considered an attempt to distance oneself from potential criminal consequences.

More than 200 confirmed victims
Guardio Labs has already confirmed 200 unique victims, with the number estimated to be increasing daily.
Researchers have initiated notifications to those affected, however the true extent of the campaign remains unclear.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted
The incident highlights a worrying trend: cybercriminals are now investing in search engine manipulation, exploiting users' trust in sponsored results.
For professionals managing critical web infrastructure, the message is clear. Access to services like ManageWP should be done exclusively via saved bookmarks or manual URL entry, while the use of hardware-based 2FA is now a basic line of defense against the new generations of AiTM attacks.
Source: www.bleepingcomputer.com
