- Patchstack discovered a new phishing -campaign that targeted WOOCOMMERCE -Users
- The E email warns users of a “critical vulnerability” to be corrected
- “Fix” is actually malware that creates a rogue admin account and drops of stage to malware
If you are a WOOCOMMERCE user, pay attention as there is a new phishing campaign that goes around targeting people like yourself.
Recently, Security Scientists from Patchstack discovered a new phishing attack, which they described as “large scale” and “sophisticated”. In the attack, Crooks sent an E email and warned their target of a critical vulnerability on their sites to be treated immediately.
The e -mail also comes with a “Download Patch” link that, instead of the supposed solution, actually implements a malicious WordPress plugin. Plugin is hosted on a site that mimics the market[.]com ”(Note ė character).
Old actors or new copycats?
The plugin only hides itself from the list of installed plugins and then creates a new admin account. It also hides this report from the victim and forward the credentials to the attacker. Finally, the stage to Malware, which includes web shells such as PAS-FORK, P0WNY and WSO.
Patchstack, which usually tracks WordPress threats, says a similar campaign was observed back in December 2023, with the most important difference that the phishing email warned of a non-existent CVE. Since both E emails and malware are pretty similar, the researchers speculate that both attacks are either the work of the same threat actor or that the new campaign is the work of a copycat,
“They claim that the targeted sites are influenced by a (non-existent) ‘unauthorized administrative access’ vulnerability, and they encourage you to visit their phishing site, which uses an IDN Homogram attack to hide as the official Woocommerce site,” researchers explained.
If you are running a WordPress site with WOOCOMMERCE installed, scan your site by suspicious plugins and admin accounts, and be sure to update both WordPress and the plugins/themes you are running.
Via Hacker the news