A newly analyzed WordPress malware implant combines must-use plugin persistence, hidden administrator accounts, credential theft, cross-site propagation, and Ethereum-based EtherHiding to create an unusually resilient backdoor. The malicious code masquerades as an automated health-check and reporting plugin, using plausible plugin metadata, an author name, and a repository link to reduce suspicion. It is installed as […]
Read the original article:
