Skip to content
WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered

WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered

First seen 16 Jun 2026, 20:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 20:17 UTC
  • A Turkish-speaking threat actor is behind a multi-stage WordPress infection using dual web shells.
  • GULoader malware is being delivered through compromised WordPress sites via a sophisticated chain.
  • Both incidents emphasize the need for enhanced security measures for WordPress installations.

Recent investigations revealed two significant cybersecurity incidents involving compromised WordPress sites. The first incident involved a Turkish-speaking threat actor using a fake plugin to drop dual PHP web shells via database injection, targeting Private Blog Networks (PBNs) for SEO monetization. The second incident exploited WordPress mu-plugins to deliver GULoader malware through a complex EtherHiding chain. Both attacks highlight the vulnerabilities in WordPress, affecting numerous sites in the gambling and adult affiliate sectors. The campaigns are ongoing, with evidence of user-initiated attack paths and remote command-and-control capabilities. Security professionals are urged to monitor for signs of these threats and implement protective measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-16
WordPress PBN infection discovered
A multi-stage infection was identified involving a fake plugin and dual web shells targeting SEO monetization.
Blog.Sucuri
2026-06-16
GULoader delivery chain identified
Compromised WordPress sites were used to deliver GULoader through an EtherHiding chain, confirmed by sandbox analysis.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track GuLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed