WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered

WordPress Exploits: Dual Webshells and GULoader Delivery Chain Uncovered

First seen 16 Jun 2026, 20:28 UTC GbhackersBlog.Sucuri 71% similarity 69.5

Article Content

Browse articles
ThreatCluster

Recent investigations revealed two significant cybersecurity incidents involving compromised WordPress sites. The first incident involved a Turkish-speaking threat actor using a fake plugin to drop dual PHP web shells via database injection, targeting Private Blog Networks (PBNs) for SEO monetization. The second incident exploited WordPress mu-plugins to deliver GULoader malware through a complex EtherHiding chain. Both attacks highlight the vulnerabilities in WordPress, affecting numerous sites in the gambling and adult affiliate sectors. The campaigns are ongoing, with evidence of user-initiated attack paths and remote command-and-control capabilities. Security professionals are urged to monitor for signs of these threats and implement protective measures.

Key Points: • A Turkish-speaking threat actor is behind a multi-stage WordPress infection using dual web shells. • GULoader malware is being delivered through compromised WordPress sites via a sophisticated chain. • Both incidents emphasize the need for enhanced security measures for WordPress installations.

ThreatCluster AI How this analysis works

Timeline

2026-06-16
WordPress PBN infection discovered
A multi-stage infection was identified involving a fake plugin and dual web shells targeting SEO monetization.
Blog.Sucuri
2026-06-16
GULoader delivery chain identified
Compromised WordPress sites were used to deliver GULoader through an EtherHiding chain, confirmed by sandbox analysis.
Gbhackers

Community

Browse all →

Tracked Entities in This Story