Blog.Sucuri
WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Recent investigations revealed two significant cybersecurity incidents involving compromised WordPress sites. The first incident involved a Turkish-speaking threat actor using a fake plugin to drop dual PHP web shells via database injection, targeting Private Blog Networks (PBNs) for SEO monetization. The second incident exploited WordPress mu-plugins to deliver GULoader malware through a complex EtherHiding chain. Both attacks highlight the vulnerabilities in WordPress, affecting numerous sites in the gambling and adult affiliate sectors. The campaigns are ongoing, with evidence of user-initiated attack paths and remote command-and-control capabilities. Security professionals are urged to monitor for signs of these threats and implement protective measures.
Key Points: • A Turkish-speaking threat actor is behind a multi-stage WordPress infection using dual web shells. • GULoader malware is being delivered through compromised WordPress sites via a sophisticated chain. • Both incidents emphasize the need for enhanced security measures for WordPress installations.