Warning for Wordpress users

chayton

aka LooHoo
webmeister
PABnonaccred
CAG
Joined
Jun 5, 2006
Location
Edmonton Canada
Just got an email from Wordfence about a phishing mail targeting Wordpress users into downloading what they think is a security patch. The email looks like this below, the link goes to a landing page that looks legit, but the security patch is actually a backdoor for a hidden admin user, plus another backdoor which includes a file manager, SQL client, and command line terminal to maintain control over the site.

1701475226301.png

Things to watch out for:

1701475593512.png

Read more here:
You do not have permission to view link Log in or register now.
 
Thanks Cindy!!

Just goes to show that everyone needs to be vigilant about this. I get daily emails from the casinomeister.com admin saying I need to change my passwords ASAP with an expiring link to do so. If we were a huge company with loads of lower level employees, we'd be in a mess.
 
If I'd gotten this email I'd have noticed the typo right away (Excecution) plus the "Dear user" seems scammy to me. But the link going to en-gb-wordpress[dot]org and the fake landing page almost looks legit so I wanted to share it just in case.

Honestly anyone who uses Wordpress should sign up for the Wordfence mailing list, I get several emails a week with info on plugin vulnerabilities and hacked themes and other stuff they've found. Although since I've been getting it, it makes me wonder if Wordpress is really worth the constant bloody hassle. :rolleyes:
 

Users who are viewing this thread

Meister Ratings

Back
Top