216.73.216.226

Analysis of a Malicious WordPress Plugin: The Covert Redirector

· Published 19/06/2025 01:56 · Modified 23/06/2025 20:12

Export JSON

Essential information

Published
19/06/2025 01:56
Modified
23/06/2025 20:12
Tags
2025-06-19 c2 plugin redirect seo website-integrity websocket wordpress wordpress-player.php
Related entities
1 observables, 6 techniques (mitre), 1 others

Description

A malicious named '' has been discovered, affecting at least 26 websites. The injects a hidden HTML5 video player and establishes a connection to a command and control server. It redirects visitors to suspicious websites after 4-5 seconds, avoiding execution for logged-in users. The malware uses a fake ' Core' author name to evade detection. It impacts website integrity through unauthorized redirects, degradation, and potential security risks to visitors. Mitigation steps include thorough scanning, malware removal, credential resets, software updates, and implementing a Web Application Firewall.

External references