Die #WordPress Backdoor Hölle ganz modern. 🔥
Es gibt recht kompetente aber leider kriminelle Akteure die WordPress nutzen um ihr Geschäft zu betreiben: 🤢
“WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory”
Im Artikel finden sich weitere Details wo und wie WordPress-Dateien zu finden sind die den Missbrauch steuern.
Ein Überblick:
“On servers that support System V shared memory, the payload is written into a segment identified by a fixed numeric key,” Sucuri said. “That segment lives in RAM, so it survives file deletion and database cleanup alike, and on shared hosting it can even be owned by a different account.”
Der Weg der Verbreitung ist aktuell unklar:
“It’s currently not known how the malware is delivered to the WordPress site. However, typical initial access vectors include known security flaws in WordPress, plugins, and themes; weak login credentials; software supply chain attacks targeting popular plugins; and the exploitation of insecure media or form upload features to push PHP web shells into server directories.”
Sprechen Sie immer mit einem erfahrenen Spezialisten. Nur dann ist/wird es halbwegs sicher. 🙂
thehackernews.com/2026/…