
Security researchers at c/side have discovered that attackers have manipulated or taken over more than 5,000 WordPress websites. The affected websites also include a number of German-language sites. The researchers describe their findings in a blog post. Mint Secure has already informed some of the website operators and is assisting with the clean-up of affected installations.
How does the Malware work?
Essentially, the Malware creates a new account with the ID “wpx_admin” – a new administrator account designed to give the attackers continued access to the compromised WordPress site. This provides very extensive access, allowing the attackers to make any changes to the website or upload further malicious code in the future.
The most commonly deployed attacker script is now detected by mainstream antivirus systems, although these are often not in use on Linux-based web servers. The script is extremely cleverly designed and intercepts so-called CSRF tokens during user actions in order to subsequently set up the admin account as a backdoor.
The script also communicates with the following command-and-control endpoints: https://wp3[.]xyz/plugin[.]php and https://wp3[.]xyz/tdw1[.]php.
How can website operators determine whether they are affected?
Website operators should check carefully whether they are affected and examine their WordPress installation for potential backdoors created by newly added accounts, themes and plugins. Of particular importance is checking for the administrator account “wpx_admin” and for communication with the command-and-control endpoints mentioned above.
Mint Secure GmbH
How Mint Secure can help you
If you are affected, please do not hesitate to contact us so that we can provide you with comprehensive support. In addition to an initial forensic analysis, we will also assist you with the complete clean-up and restoration of your website.
Initial forensic analysis
Rapid investigation of your WordPress installation for compromise, backdoors and malicious code.
Clean-up & Restoration
Complete clean-up of compromised installations and secure restoration of your website.
Incident Response
A structured response to security incidents, including root cause analysis and protection against further attacks.
Has your website been affected? We’ll help you clean it up quickly and easily. Get in touch now.
Conclusion
The WP3[.]XYZ Malware campaign has already compromised more than 5,000 WordPress sites, creating a permanent backdoor via a hidden admin account (“wpx_admin”). Anyone running a WordPress site should immediately check for unknown administrator accounts and suspicious network activity.
A rapid forensic analysis and thorough clean-up are crucial to preventing lasting damage and further misuse of the website.
Mint Secure can assist you with the analysis and remediation of affected WordPress installations. Please get in touch.

