Security firms Wordfence and PatchStack have warned WordPress admins about phishing emails that impersonate the legitimate WordPress.com site and trick victims into installing a malicious plugin. The “plugin” reportedly exfiltrates website data, downloads a backdoor and remains hidden on the site’s root directory.

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails – The Hacker News
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails The Hacker News


