Backed by Awesome Motive.
Learn more on our Seahawk Blog.

Linux Backdoor Malware Targets Outdated WordPress Themes and Plugins

Written By: author image Komal Bothra
author image Komal Bothra
Hey, I’m Komal. I write content that speaks from the heart and makes WordPress work for you. Let’s make your ideas come alive!
Linux Backdoor Malware Targets WordPress

Security firm Doctor Web has discovered a malicious Linux program that targets WordPress sites running outdated and vulnerable plugins and themes. The malware is designed to exploit 30 theme and plugin vulnerabilities to inject malicious JavaScript into websites, redirecting visitors to the attacker’s chosen website. It has been active for over three years and has been updated to target additional vulnerabilities. 

The malware targets 32-bit versions of Linux but can also run on 64-bit versions. There are two versions of the malware: Linux.BackDoor.WordPressExploit.1 and Linux.BackDoor.WordPressExploit.2. The latter includes an updated server address for distributing the malicious JavaScript and an expanded list of exploited vulnerabilities. Doctor Web’s report speculates that attackers may have a long-term plan to retain administrative access even after users update to newer, patched versions of the compromised plugins.

Doctor Web has released a document containing indicators of compromise for the Linux backdoor malware infecting WordPress websites. The document includes hashes, IP addresses, and domains used by the malware in its attacks. Security professionals and WordPress administrators can use this information to detect and prevent further infections.

To protect against this threat, it is essential for WordPress users to keep their themes and plugins up to date and to use strong, unique passwords. It is also a good idea to use a web application firewall and to regularly scan for malware.

If you suspect that your WordPress site has been compromised, it is essential to take immediate action to secure it and prevent further damage. This may include restoring the site from a backup and installing security measures to prevent future attacks.

Related Posts

It’s that time of the year again – the final major update has landed, and

Automattic Inc., the parent company behind WordPress.com, WooCommerce, and Tumblr, announced its acquisition of Texts.com,

Cybersecurity is at the forefront of every enterprise and government organization’s concerns in the contemporary

Komal Bothra September 7, 2024

Best Twitter (X) Plugins for WordPress 

With Twitter’s transformation into X, the social media landscape is shifting—and so should your website!

WordPress
Komal Bothra September 7, 2024

How to Setup Elementor Shortcodes for Easy Template Use

Ever wished you could instantly add beautiful WordPress designs anywhere on your WordPress website without

WordPress
Komal Bothra September 6, 2024

Easily Fix “the package could not be installed. The theme is missing the style.css stylesheet” in WordPress

We’ve all been there—excitedly uploading a new theme to our WordPress site, only to be

WordPress

Get started with Seahawk

Sign up in our app to view our pricing and get discounts.