Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » WooCommerce users are oriented
Global Security

WooCommerce users are oriented

AdminBy AdminApril 28, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


April 28, 2025Red LakshmananSea -safety / malicious software

Cybersecurity researchers warn of a large -scale phishing campaign aimed at WooCommerce users with a fake security warning calling them to load a “critical patch” but instead deploy the back.

WordPress Patchstack’s security company called the activity as a complex and variant of another company observe In December 2023, this used fake Cve Ploy to violate sites that control the popular content management system (CMS).

Given the similarity of e -mail phishing baits, fake web pages and the same methods used to hide malware, it is believed that the last wave of the attack is either the work of the same threat actor, or this is a new cluster that carefully imitates the former.

Cybersecurity

“They declare IDN Homograph Attack To disguise yourself as an official WooCommerce “site, a security researcher – Note.

Financial Email recipients are calling for a “download patch” link to download and install the intended security fix. However, this redirects them to a fake WooCommerce market, located on the “WooComMėRce” domain (.) Complay the use of “ė” instead of “e”), where you can download the archive zip (“AuthbyPasse-update-31297-IDIP”).

The victims are then offered to install the patch because they install any ordinary WordPress plugin, effectively unleashing the following series of malicious action –

  • Create a new user at an Administrator level with a difficulty username and randomized password after setting by accident named Cron’s assignment that works every minute
  • Send HTTP to receive an external server request (“WooCommerce-Services (.) Com/WPAPI”) with the username and password, as well as URL infected site
  • Send HTTP to receive the download request for the next stage of the embarrassed load from another server (“WooCommerce-Help (.) Com/Active” or “WooCommerce-API (.) Com/Active”
  • Private a useful load to retrieve multiple web fellows such as PAS-FORK, P0WNY and WSO
  • Hide the malicious plugin from the plugin list and hide the created administrator account
Cybersecurity

The pure result of the company is that it allows the attackers remote control over the sites, allowing them to introduce spam or sketch ads, redirect site visitors to fake sites, record a broken server in Botnet for DDOS attacks and even registered server resources as part of the drawing scheme.

Users are advised to scan your instances on suspicious plugins or administrator accounts, and make sure the software is relevant.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.