WordPress -Webot targeted by malicious plugin disguised as a security tool


  • Wordfence -Scientists reveal a new piece of WordPress -Malware
  • Threat actors used AI to create legitimate looking tools
  • Malware pretending to be an anti-malware product

Security researchers have discovered a piece of WordPress malware that pretends to be an antimalware solution. At the end of April, Marko Wotschka from the Wordfence team released a new blog post with details about an “interesting WordPress Malware”: It appears in the file system as a normal WordPress plugin, often named ‘WP-Antymalwary-Bot.php’.

While looking conspicuous at first, the researchers discovered that this plugin contains several features that allow attackers to continue on the target website, hide the plugin from the dashboard and externally perform code.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top