Skip to main content

WordPress Jetpack Plugin Backdoor

Attackers are exploiting compromised account credentials and the Jetpack plugin to install malicious plugins on WordPress websites.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Attackers are exploiting compromised account credentials and the Jetpack plugin to install malicious plugins on WordPress websites.

Threat details

The threat actors initially gather usernames and passwords from public sources. They then attempt to use these to gain access to WordPress.com accounts. Once they have gained access to an account, they check if it uses the Jetpack plugin to manage any external self-hosted WordPress websites. If this is the case, they use the Jetpack dashboard panel to install malicious plugins on those websites.

The deployed plugins redirect users to scam web pages. They appear on the WordPress.com dashboard, but are not shown on the targeted websites' plugin lists.


Remediation steps

Type Step
  • Enable Two Factor Authentication on WordPress.com accounts.
  • Review plugins that have been deployed across self-hosted sites using the WordPress.com dashboard.
  • Review any logs for affected websites.
  • Remove any malicious plugins or restore affected websites from their most recent backup.

Last edited: 17 February 2020 12:57 pm