
Image by Souvik Banerjee, from Unsplash
New Malware Disguises as Anti-Malware Plugin on WordPress
A new WordPress malware disguised as an anti-malware plugin grants attackers remote access, with updated security measures being rolled out by Wordfence.
In a rush? Here are the quick facts:
- New malware, “WP-antymalwary-bot.php,” disguises itself as an anti-malware plugin on WordPress.
- Malware grants attackers access to site dashboards and executes remote code.
- Attackers can inject malicious JavaScript and redirect visitors to harmful sites.
A new variant of malware has been discovered on WordPress sites, disguised as a legitimate anti-malware plugin. Identified by Wordfence security analysts as “WP-antymalwary-bot.php,” this malware allows attackers to access site dashboards while remaining invisible to admin views, and as a result, it enables the remote execution of harmful code.
The malware was first detected by Wordfence on January 22, 2025, during a routine site cleanup.The plugin functions as an ordinary WordPress tool yet contains a backend command feature that enables attackers to perform administrator logins.
The malware maintains contact with a Command & Control (C&C) server, allowing attackers to issue remote commands. It also enables attackers to distribute malware by adding malicious JavaScript code to other directories.
To make matters worse, Wordfence reports that the malware hides itself from the WordPress plugin list, making it even harder for website owners to spot. It also uses the WordPress task scheduler to maintain its presence on the site. This means that if the malicious plugin is removed, the malware can simply reappear after the site is visited again.
The malware also communicates with a server in Cyprus, reporting back information and possibly receiving further instructions. Wordfence reports that new versions of the malware continue to emerge, including one that schedules regular events to keep the attack going.
Experts recommend WordPress users stay vigilant and update their security plugins.