WordPress Jetpack Plugin Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The threat actors initially gather usernames and passwords from public sources. They then attempt to use these to gain access to WordPress.com accounts. Once they have gained access to an account, they check if it uses the Jetpack plugin to manage any external self-hosted WordPress websites. If this is the case, they use the Jetpack dashboard panel to install malicious plugins on those websites.
The deployed plugins redirect users to scam web pages. They appear on the WordPress.com dashboard, but are not shown on the targeted websites' plugin lists.
Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:57 pm