Blog.Sucuri WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered
Article Content
- •A Turkish-speaking threat actor is behind a multi-stage WordPress infection using dual web shells.
- •GULoader malware is being delivered through compromised WordPress sites via a sophisticated chain.
- •Both incidents emphasize the need for enhanced security measures for WordPress installations.
Recent investigations revealed two significant cybersecurity incidents involving compromised WordPress sites. The first incident involved a Turkish-speaking threat actor using a fake plugin to drop dual PHP web shells via database injection, targeting Private Blog Networks (PBNs) for SEO monetization. The second incident exploited WordPress mu-plugins to deliver GULoader malware through a complex EtherHiding chain. Both attacks highlight the vulnerabilities in WordPress, affecting numerous sites in the gambling and adult affiliate sectors. The campaigns are ongoing, with evidence of user-initiated attack paths and remote command-and-control capabilities. Security professionals are urged to monitor for signs of these threats and implement protective measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track GuLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…