216.73.216.233

Hidden WordPress Backdoors Creating Admin Accounts

· Published 24/09/2025 10:31 · Modified 24/09/2025 12:33

Export JSON

Essential information

Published
24/09/2025 10:31
Modified
24/09/2025 12:33
Tags
2025-09-24 admin accounts backdoor compromise credential-theft debugmaster pro stealth wordpress
Related entities
8 techniques (mitre), 1 malware

Description

Two malicious files were discovered on a compromised website, designed to manipulate administrator accounts and maintain unauthorized access. The first file, disguised as a plugin called '', created a secret admin user and communicated with a command and control server. The second file, 'wp-user.php', ensured a specific admin user with a known password was always present. Both files worked together to create a robust system for persistent access, allowing attackers to control the site, inject spam, redirect visitors, or steal information. The malware also injected malicious scripts for visitors and tracked admin IPs. Cleaning requires removing the files, auditing accounts, resetting credentials, and hardening the site against reinfection.

External references