Steam community profiles misused as C2 network in new WordPress malware infection campaign


  • Malware hides payload in Steam Community comments
  • WordPress sites are used to host backdoors
  • Nearly 2,000 websites compromised since July

Security researchers from GoDaddy found a brazen new malware campaign that used comments from Steam Community accounts as command-and-control (C2) infrastructure.

Here’s how the attack plays out: The attackers would first find vulnerable WordPress sites, or those protected by weak credentials, and use them to host PHP malware somewhere in the site’s files. For example, the sample was found in a theme’s ‘functions.php’ file. This malware contains both a JavaScript injection component and a server-side backdoor.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top