WordPress security firm Defiant has discovered a security threat in the form of a backdoor malware posing as a genuine plugin. It hides its presence and avoids detection by presenting itself as a caching plugin. Once installed, the malware provides attackers with a range of functions and gives them remote access to control and monetise the victim website.

Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HR – Help Net Security
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HR Help Net Security


