{"id":13335,"date":"2026-06-03T10:04:13","date_gmt":"2026-06-03T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/03\/wordpress-malware-abuses-steam-community-profiles-for-c2-operations\/"},"modified":"2026-06-03T10:04:13","modified_gmt":"2026-06-03T10:04:13","slug":"wordpress-malware-abuses-steam-community-profiles-for-c2-operations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/03\/wordpress-malware-abuses-steam-community-profiles-for-c2-operations\/","title":{"rendered":"WordPress Malware Abuses Steam Community Profiles for C2 Operations"},"content":{"rendered":"<p>    WordPress Malware Abuses Steam Community Profiles for C2 Operations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. <\/p>\n<p class=\"wp-block-paragraph\">Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into a covert control channel.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The malware works in two stages. First, it injects malicious JavaScript into the front end of a compromised WordPress website, serving harmful content to every visitor who lands on the page. <\/p>\n<p class=\"wp-block-paragraph\">Second, it plants a server-side backdoor that gives attackers persistent remote access, allowing them to modify WordPress plugin and theme files without any visible trace of the intrusion.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">GoDaddy security researchers identified this campaign, noting it was first detected in July 2024 and has since been found across approximately 1,900 WordPress sites.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.godaddy.com\/resources\/news\/malware-targeting-wordpress-abuses-steam-community-profiles\" id=\"https:\/\/www.godaddy.com\/resources\/news\/malware-targeting-wordpress-abuses-steam-community-profiles\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GoDaddy\u00a0said in a report<\/a> shared with Cyber Security News (CSN) that threat actors are deliberately disguising their infrastructure behind Valve\u2019s trusted gaming platform rather than maintaining obviously malicious servers that could be flagged and taken down quickly.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">What makes this campaign particularly difficult to detect is how the malware conceals its payloads. It uses invisible Unicode characters, a technique known as steganography, to <a href=\"https:\/\/cybersecuritynews.com\/cybercriminals-use-malicious-cybersquatting-attacks\/\" id=\"141790\" target=\"_blank\" rel=\"noreferrer noopener\">encode malicious data within Steam profile<\/a> comment text. <\/p>\n<p class=\"wp-block-paragraph\">Since those hidden characters look like completely normal text on the surface, traditional text-based scanning tools are far less likely to catch them during routine checks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiMsCkEGzHNmEO3hJ7DtcIZomUmlVO11WQ7gWT5lF8kt5gPjK-vPwPBARxPfv4jpS-hdcW1q8tps62B1i9QYNyfXCemknT2_lH4rDyL16_7bkfk8x3ZgtSj5jEpmXzMYXxUvsW45m6joIjJiDxIZYdMKMvjbrW2KB44hxbdkDT9ZAco6izZ9-udLVJzhto\/s16000\/Example%2520of%2520Steam%2520commentthread_comment_text%2520content%2520%28Source%2520-%2520GoDaddy%29.webp?ssl=1\" alt=\"Example of Steam commentthread_comment_text content (Source - GoDaddy)\"><figcaption class=\"wp-element-caption\">Example of Steam commentthread_comment_text content (Source \u2013 GoDaddy)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The reach of this campaign is significant. Compromised websites unknowingly serve injected scripts to every visitor, exposing real users to potential harm. For site owners, the damage runs deeper, as the backdoor gives attackers the ability to rewrite site code even after partial cleanup attempts.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\"><\/a><\/p>\n<h2 id=\"h-wordpress-malware-abuses-steam-community-profiles\" class=\"wp-block-heading\"><strong>WordPress Malware Abuses Steam Community Profiles<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The core of this attack relies on a PHP function embedded within the compromised WordPress installation. <\/p>\n<p class=\"wp-block-paragraph\">When any page on the infected site loads, <a href=\"https:\/\/cybersecuritynews.com\/malware-analysis\/\" id=\"82355\" target=\"_blank\" rel=\"noreferrer noopener\">the malware sends an HTTP request to a Steam Community<\/a> profile page using cURL, scrapes comment text from that profile, and decodes hidden payloads embedded inside it.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The malware has been observed fetching profiles such as steamcommunity.com\/profiles\/76561199096946028 and caches extracted content using WordPress transients with a five-minute expiration window. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjH2SZ8NWQlw-4NVtrB54di88HVt-KvflUQEyvVKfXx_ItznOSi_pczAZ5wcTPnE6A4sdghLZ9HH_YWR-mzinryUZKNrBvvZ7vvOpQTJwtYkPHBDU8QwHJH0fPFOh9AYbJgOYiVDIWa0AHSuEgRysap1Jkh9i1UcuD-emg_TPwTYQNOSC1nMCSgK6pWJWo\/s16000\/PublicWWW%2520results%2520showing%2520websites%2520loading%2520hello-mywordl%255B.%255Dinfo%2520%28Source%2520-%2520GoDaddy%29.webp?ssl=1\" alt=\"PublicWWW results showing websites loading hello-mywordl[.]info (Source - GoDaddy)\"><figcaption class=\"wp-element-caption\">PublicWWW results showing websites loading hello-mywordl[.]info (Source \u2013 GoDaddy)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The decoded data becomes a JavaScript URL injected into every front-end page via the wp_enqueue_script hook, under the deceptive handle name \u201casahi-jquery-min-bundle\u201d designed to mimic a legitimate library. <\/p>\n<p class=\"wp-block-paragraph\">The decoded external URL observed during analysis pointed to hello-myworld[.]info, which serves the final malicious JavaScript payload to site visitors.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-stealthy-backdoor-enables-remote-code-execution\" class=\"wp-block-heading\"><strong>Stealthy Backdoor Enables Remote Code Execution<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The server-side component is just as dangerous as the front-end injection. A backdoor function registered through WordPress\u2019s template_redirect hook listens for POST requests containing specific authentication cookies. <\/p>\n<p class=\"wp-block-paragraph\">When those cookies are present, the backdoor either confirms it is active by returning a version string, or accepts base64-encoded PHP code and rewrites plugin and theme files across the entire WordPress installation.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">This remote code execution capability means that even if a site owner removes part of the infection, attackers can reinstall deleted code through the still-active backdoor. <\/p>\n<p class=\"wp-block-paragraph\">The malware protects this channel using AES-256-CTR encryption with PBKDF2 key derivation based on SHA-512 and 10,000 iterations, along with HMAC-SHA256 authentication to verify each incoming payload.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">To evade detection, <a href=\"https:\/\/cybersecuritynews.com\/researchers-detailed-apt28s-hta-trojan-multi-layer-obfuscation-techniques\/\" id=\"94791\" target=\"_blank\" rel=\"noreferrer noopener\">the malware layers multiple obfuscation techniques<\/a>. All string constants are encoded using octal or hexadecimal escape sequences, function and variable names follow a randomized mixed-case hexadecimal style, and a disabled logging function is scattered through the code to mimic legitimate debugging infrastructure without ever executing.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Site administrators who suspect an infection should enable maintenance mode right away and back up the compromised installation before making any changes. <\/p>\n<p class=\"wp-block-paragraph\">All WordPress credentials including admin passwords, database access, FTP credentials, and SSH keys must be rotated. Cleanup must cover every plugin and theme file, since partial removal is not enough given the backdoor\u2019s ability to remotely restore deleted code. <\/p>\n<p class=\"wp-block-paragraph\">Suspicious transient cache entries with the prefix\u00a0<em>transient_caption<\/em>\u00a0and enqueued external scripts pointing to unknown domains should be removed.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/98400c7f-9346-41bc-88e8-21c02b5cce58\/WordPress-Malware-Abuses-Steam-Community-Profiles-for-C2-Operations.pdf?AWSAccessKeyId=ASIA2F3EMEYETP2SQXGT&amp;Signature=zWYo5BSY72ZIa1ZPReXwUWfae7k%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJHMEUCIQDq2b3sYquDO73fy73RxHM0yEHryytvso2brLeBHMPUsQIgYXUsqE%2FQZ%2FPOh217aCj4UZ%2FYsVU50xSta0uY4a7uO58q8wQIKBABGgw2OTk3NTMzMDk3MDUiDPfX2dxySvoTEY%2FsfyrQBPBd0cXHXlZjWEtna%2FfIoEGmkCXmZ%2FL3P2Zpd5UmMnBKU4UpxxcspR4iOv%2B2Rt%2FYrCl%2FSPdDOtZSaDOqhNTccSjjZentdI4yvMSk%2F3QnmAadABkiyBiaApDGGNH0b%2BJDTD7Z9pygIzqVOQrRjzHmWr%2FST5NEizB3sJGfHlspFfdqe0mroG1JFmGFoRUM1Yn8vCT%2F20U2bUqn35CSBhuxKbuVfEuwv8by35oLGYlRPcKhbPofS%2F9GRGdHjZk96gjfEyv0O9PzIX6an4OkzoSTPTHq5QGT6w9n3tKLc9ltm21XxK1Vc6SjVZR948kGJ2RFAlff1fG%2BaJo3K1jUn2xkth%2BA2fTsYzu7%2BADVVSWCJe9sZiBtwNyGPUQtHePQpy5%2BP8O%2FnInnhV2q38bZWZFLmO%2By1%2FJxVhp5O9sOxym5863UROXcqwmfpuW3%2FrBv2WgNANM6miVJxTsacXgVIhywQNaheAks8GkS1qp9KD7s5Xe0fviNCzlIjL6elsk9INVdY5AwtNBWcxhOI0Dx4H5vUGtNoK9JULRCHPd1stxyFoTBfv4OzFp43h35R2hHB6%2FnirKU0%2FiBQhZerscq2ld5cI34iLnIwXay%2BY8ggGnsZeB%2B3OsXiaX4082%2BMIzyS2DShmehFNQxS56LqzhU1hcX1dqkI4tPNazPPMoVN6pS%2BK4NJYwm9UmcbZQAwp4%2B%2BacAqPE1PJ1V9w2f7J914LqroRTRDMKmR%2BG3vFqZNw0W0XIFgr0khi9mE4BSLJRGUEZaamdwRJsiRFYV5IWLPpKEMPYwhNX70AY6mAElq5BXmPx%2Bpu0zfPPar%2FPMoOwvKEKSqMtQzqT7rRNCtphakiNorg1RQYt7p6AYNLcKhWoLmUT6ixgNjI9t5daJpMBeN39EdP1IhD6HiYkp5dpLVO5oRkoNSZG4KuT2R4Eyd%2FuhDfcgIeLrfeHHM767Yjr5YTt1GIiZYZl0tr14NmR4yw81JLfNiJRRpMy2ognvJVPsE4R9oQ%3D%3D&amp;Expires=1780412827\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>Type<\/strong><\/th>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>Indicator<\/strong><\/th>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>Description<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/steamcommunity.com\/profiles\/76561199096946028\/<\/td>\n<td>Steam profile used to host encoded C2 payloads<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/steamcommunity.com\/id\/ravypadliha<\/td>\n<td>Steam profile observed during malware fetching<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/steamcommunity.com\/id\/enomisvool123\/<\/td>\n<td>Steam profile observed during malware fetching<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>https:\/\/steamcommunity.com\/id\/eremohnf342<\/td>\n<td>Steam profile observed during malware fetching<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>hello-myworld[.]info<\/td>\n<td>External domain serving the decoded malicious JavaScript payload<\/td>\n<\/tr>\n<tr>\n<td>Cookie Name<\/td>\n<td>DEpjndDbNc<\/td>\n<td>Authentication cookie used to trigger backdoor ping\/keepalive response<\/td>\n<\/tr>\n<tr>\n<td>Cookie Name<\/td>\n<td>tEcaKKXEsb<\/td>\n<td>Authentication cookie used to trigger remote code execution via backdoor<\/td>\n<\/tr>\n<tr>\n<td>File Path<\/td>\n<td>\/wp-content\/themes\/gt3-child\/functions.php<\/td>\n<td>File path where malware was initially discovered<\/td>\n<\/tr>\n<tr>\n<td>Handle Name<\/td>\n<td>asahi-jquery-min-bundle<\/td>\n<td>Deceptive script handle name used to inject malicious JavaScript<\/td>\n<\/tr>\n<tr>\n<td>Transient Prefix<\/td>\n<td><em>transient_caption<\/em><\/td>\n<td>WordPress transient cache prefix used to store C2 data<\/td>\n<\/tr>\n<tr>\n<td>Function Name<\/td>\n<td>Ce8d26cADf211699<\/td>\n<td>PHP function responsible for fetching Steam profile content<\/td>\n<\/tr>\n<tr>\n<td>Function Name<\/td>\n<td>EdF20922Ff709e68<\/td>\n<td>PHP function performing cryptographic decoding of payloads<\/td>\n<\/tr>\n<tr>\n<td>Function Name<\/td>\n<td>G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72<\/td>\n<td>PHP function injecting decoded script into WordPress front end<\/td>\n<\/tr>\n<tr>\n<td>Function Name<\/td>\n<td>mpzZYIbGOb<\/td>\n<td>PHP backdoor handler function registered via template_redirect<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/wordpress-malware-abuses-steam\/\">WordPress Malware Abuses Steam Community Profiles for C2 Operations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/wordpress-malware-abuses-steam\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress Malware Abuses Steam Community Profiles for C2 Operations A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13335","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13335"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13335"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13335\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}