back-2 (2)

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites

Share:

A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data.

Researchers at webscript security company c/side discovered during an incident response engagement for one of their clients that the malicious activity uses the wp3[.]xyz domain to exfiltrate data but have yet to determine the initial infection vector.

After compromising a target, a malicious script loaded from the wp3[.]xyz domain creates the rogue admin account wpx_admin with credentials available in the code.

Creating a rogue admin account
Creating a rogue admin account
Source: c/side

The script then proceeds to install a malicious plugin (plugin.php) downloaded from the same domain, and activates it on the compromised website.

According to c/cide, the purpose of the plugin is to collect sensitive data, like administrator credentials and logs, and send it to the attacker’s server in an obfuscated way that makes it appear as an image request.

The attack also involves several verification steps, such as logging the status of the operation after the creation of the rogue admin account and verifying the installation of the malicious plugin.

Blocking the attacks

c/side recommends that website owners block the ‘wp3[.]xyz’ domain using firewalls and security tools.

Moreover, admins should review other privileged accounts and the list of installed plugins, to identify unauthorized activity, and remove them as soon as possible.

Finally, it is recommended that CSRF protections on WordPress sites be strengthened via unique token generation, server-side validation, and periodic regeneration. Tokens should have a short expiration time to limit their validity period.

Implementing multi-factor authentication also adds protection to accounts with credentials that have already been compromised.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:40 pm, May 12, 2025
weather icon 15°C
L: 13° | H: 17°
few clouds
Humidity: 79 %
Pressure: 1014 mb
Wind: 2 mph SE
Wind Gust: 2 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 19%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:13 am
Sunset: 8:40 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
13° | 17°°C 0.28 mm 28% 12 mph 79 % 1020 mb 0 mm/h
Wed May 14 10:00 pm
weather icon
11° | 22°°C 0 mm 0% 9 mph 74 % 1023 mb 0 mm/h
Thu May 15 10:00 pm
weather icon
9° | 18°°C 0 mm 0% 12 mph 78 % 1025 mb 0 mm/h
Fri May 16 10:00 pm
weather icon
8° | 21°°C 0 mm 0% 10 mph 84 % 1026 mb 0 mm/h
Sat May 17 10:00 pm
weather icon
9° | 22°°C 0 mm 0% 9 mph 86 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0.22 mm 22% 2 mph 78 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 14°°C 0 mm 0% 3 mph 79 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0 mm 0% 4 mph 78 % 1017 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 8 mph 52 % 1018 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 9 mph 42 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
21° | 21°°C 0.28 mm 28% 12 mph 44 % 1018 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
18° | 18°°C 0.1 mm 10% 10 mph 43 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 7 mph 60 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,424.77
-1.67%
Ethereum(ETH)
€2,233.70
-1.14%
Tether(USDT)
€0.90
-0.02%
XRP(XRP)
€2.28
6.86%
Solana(SOL)
€155.45
-0.08%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.206279
-1.02%
Shiba Inu(SHIB)
€0.000014
-1.53%
Pepe(PEPE)
€0.000013
-0.33%
Peanut the Squirrel(PNUT)
€0.348343
-6.25%
Scroll to Top