216.73.216.6

Stealthy PHP Malware Uses ZIP Archive to Redirect WordPress Visitors

· Published 14/07/2025 13:50 · Modified 14/07/2025 14:17

Export JSON

Essential information

Published
14/07/2025 13:50
Modified
14/07/2025 14:17
Tags
2025-07-14 seo poisoning wordpress
Related entities
3 observables, 5 techniques (mitre)

Description

A sophisticated piece of malware was discovered embedded in a site's core files, specifically in wp-settings.php. The malware uses a ZIP archive to hide malicious code and perform search engine poisoning and unauthorized content injection. It employs dynamic Command and Control server selection, anti-bot mechanisms, and manipulates SEO-related files. The malware's main goals include manipulating search engine rankings, injecting spam content, and performing unauthorized redirects. It uses obfuscation techniques and ZIP archives for code inclusion, making it challenging to detect and remove. Prevention measures include keeping software updated, using reputable sources for themes and plugins, implementing strong credential security, utilizing a Web Application Firewall, and regularly scanning for malware.

External references