WordPress Malware Hides C2 Payloads in Steam Profiles
TL;DR. A new malware campaign infects WordPress sites, using Steam Community profile comments to conceal command-and-control data. - The attackers encode malicious payloads within invisible Unicode characters in benign-looking Steam comments. - This method allows the threat actor to avoid maintaining separate C2 infrastructure and bypass traditional detection. - Nearly 2,000 WordPress websites were infected by this sophisticated evasion technique.
- Malware on WordPress sites uses Steam profiles for C2.
- Invisible Unicode characters hide payloads in Steam comments.
- GoDaddy security identified 1,980 infected WordPress sites.
- Attackers avoid C2 infrastructure and evade detection.
Sources
- WordPress malware campaign hides payloads in Steam profiles — bleepingcomputer.com