Credit Card Skimmer and Backdoor on WordPress E-commerce Site
A sophisticated malware attack targeting WordPress WooCommerce sites was discovered, involving multiple components: a credit card skimmer, a hidden backdoor file manager, and a reconnaissance script. The attack focused on financial gain and long-term control. The skimmer, injected into the checkout page, collected payment and billing information, sending it to a malicious server. A PHP backdoor allowed remote system command execution, while a reconnaissance script gathered server information. The attack demonstrates the evolving complexity of e-commerce platform threats, emphasizing the need for strict security measures, regular scans, proper access controls, and timely updates to prevent such exploits.
Pulse ID: 67d52aad906732f7bad24dfa
Pulse Link: https://otx.alienvault.com/pulse/67d52aad906732f7bad24dfa
Pulse Author: AlienVault
Created: 2025-03-15 07:22:21
Be advised, this data is unverified and should be considered preliminary. Always do further verification.