Skip to content
Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

First seen 7 May 2026, 11:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 8, 2026 at 11:38 UTC
  • Hackers are using Google Ads to deliver a phishing campaign targeting ManageWP users.
  • The attack employs an adversary-in-the-middle setup to capture credentials and 2FA codes.
  • Guardio Labs has confirmed 200 unique victims and infiltrated the attackers' infrastructure.

A phishing campaign exploiting Google Ads is targeting users of GoDaddy's ManageWP platform, which is used for managing multiple WordPress sites. The attackers employ an adversary-in-the-middle (AiTM) technique, creating a fake login page that captures user credentials in real-time. This fraudulent ad appears above the legitimate ManageWP listing in search results, tricking users into entering their credentials. Once logged in, victims are prompted for their two-factor authentication (2FA) codes, which the attackers also capture. Guardio Labs has identified 200 unique victims so far and has infiltrated the attackers' command-and-control infrastructure. The phishing framework appears to be privately developed, with indications of a Russian-language agreement found in the code. The campaign is significant due to the number of potential victims, as ManageWP is active on over 1 million websites.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 125d ago How this analysis works

Timeline

2026-05-06
Phishing campaign identified
Researchers at Guardio Labs reported a phishing campaign targeting ManageWP users via Google Ads.
Bleepingcomputer
2026-05-06
200 unique victims confirmed
Guardio Labs identified 200 unique victims of the phishing campaign at the time of reporting.
Bleepingcomputer
2026-05-07
Campaign dubbed 'WrongPress'
The phishing campaign has been named 'WrongPress' by cybersecurity researchers.
Cybersecuritynews
2026-05-07
Adversary-in-the-middle technique detailed
The attackers use an AiTM setup to proxy logins and capture credentials in real-time.
Gbhackers

More articles in this cluster (3)

Following this threat?

Track ManageWP in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed