Listen to this Post

A new wave of phishing attacks has been uncovered, this time targeting WooCommerce users on WordPress with fake security alerts. The attackers aim to trick website owners into downloading a malicious patch that actually opens the door for backdoor access. The campaign is a significant threat, as it employs sophisticated techniques to deceive users and gain control of their websites.
Patchstack researchers have been tracking these types of attacks for a while now, noting similarities to a similar attack from December 2023. In that case, attackers sent fake security alerts to WordPress users, warning of a supposed vulnerability. This time around, the attackers are using a fabricated “Unauthenticated Administrative Access” vulnerability as their lure. Here’s a breakdown of how the phishing campaign operates and what you need to watch out for.
The phishing campaign begins with emails claiming that the recipient’s WooCommerce website has been affected by a serious vulnerability. The email urges users to download a “critical patch” to fix this issue. However, this patch is actually a trojan designed to install a backdoor on the website.
The attack shares notable similarities with a December 2023 campaign, which also involved fake security patches. In that instance, the attackers warned about a Remote Code Execution (RCE) vulnerability and tricked users into downloading a malicious patch from an unverified source. This new phishing attack seems to be the same actors or a group copying their tactics.
The fraudulent emails warn of a fabricated “Unauthenticated Administrative Access” vulnerability and direct users to a phishing website. The site uses a clever technique known as an IDN homograph attack, where the website domain is made to look like the official WooCommerce domain, but with a subtle variation, like replacing a letter with one that looks almost identical.
When the user clicks the “Download Patch” button in the email, they are directed to a fake WooCommerce Marketplace page. This page is hosted on a malicious domain such as “woocommėrce.com,” where the “e” is replaced with a similar-looking character to fool the user.
After downloading the patch, the user installs a zip file called “authbypass-update-31297-id.zip.” This file behaves like a regular plugin during installation, but once activated, it sets up a hidden WordPress Cron job that runs every minute. The Cron job is used to create a new, hidden administrator account and send the credentials to an attacker-controlled server. The plugin then contacts another server to download and install several obfuscated PHP web shells, giving the attackers full control over the site.
These web shells can be used for a variety of malicious activities, such as injecting ads, redirecting traffic, stealing billing data, launching DDoS attacks, or conducting ransomware operations. The attackers use tactics to avoid detection, such as hiding the rogue admin account and the malicious plugin itself.
Researchers have shared indicators of compromise (IoCs) for this campaign, including a random-looking 8-character username for the new admin account and an unusual Cron job with names like “mergeCreator655.” The malicious plugin also creates suspicious folders in the wp-content/plugins/ and wp-content/uploads/ directories. Compromised websites generate outbound HTTP requests to attacker-controlled domains like “woocommerce-services.com,” “woocommerce-api.com,” and “woocommerce-help.com.”
As more users become aware of this phishing campaign, it’s likely that attackers will adapt and change their tactics, including using different domains or methods to hide their activities. WordPress website owners should remain vigilant and ensure their sites are protected against such attacks.
What Undercode Say:
Undercode emphasizes the growing sophistication of phishing campaigns targeting website administrators, especially within widely used platforms like WordPress. These attacks showcase the evolving nature of cyber threats, where malicious actors continuously refine their tactics to bypass detection systems and trick unsuspecting users.
One key takeaway from the analysis is the use of IDN homograph attacks, a clever technique that preys on the similarity between characters in different languages. This method helps attackers create fake websites that closely resemble legitimate ones, making it much harder for users to spot the phishing attempt. Such attacks are often effective because they exploit human error, which is a consistent weak point in cybersecurity.
The inclusion of web shells like P.A.S.-Fork, p0wny, and WSO is another concerning element of these attacks. These web shells allow the attackers to take full control of the compromised website, giving them the ability to inject malicious code, exfiltrate sensitive data, and even carry out large-scale cyberattacks. The fact that these attackers are actively using these tools for activities like ad injection, DDoS attacks, and ransomware operations indicates a well-organized and potentially profitable campaign.
The report’s mention of hidden administrator accounts and obfuscated Cron jobs highlights the growing trend of stealthy attack techniques. These tactics help attackers maintain control over compromised websites while evading detection by site owners and security tools. This level of stealth suggests that the attackers are experienced and well-versed in bypassing traditional security measures.
For website administrators, this serves as a crucial reminder to stay up-to-date on the latest cybersecurity practices. Regularly updating plugins, monitoring website traffic for unusual activity, and using strong authentication methods are just some of the steps that can help mitigate the risk of such attacks. Additionally, security plugins that monitor for unauthorized admin accounts or changes to Cron jobs can provide an added layer of defense.
Fact Checker Results:
- The phishing campaign detailed in the report aligns with common tactics used by cybercriminals in WordPress-specific attacks.
- The domain “woocommėrce.com” uses an IDN homograph attack, a known technique for deceiving users into visiting fake sites.
- Indicators of compromise such as unusual Cron jobs and suspicious plugin files are consistent with previously observed WordPress web shell infections.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.facebook.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




