Steam Community Profiles Abused as C2 Network in New WordPress Malware Infection Campaign


  • Malware hides payload in Steam community comments
  • WordPress Sites Used to Host Backdoors
  • Nearly 2,000 sites compromised since July

Security researchers at GoDaddy have discovered a brazen new malware campaign that used comments from Steam community accounts as command and control (C2) infrastructure.

Here’s how the attack works: Attackers would first find vulnerable WordPress websites, or those protected by weak credentials, and use them to host PHP malware somewhere in the site’s files. For example, the example was found in a theme’s “functions.php” file. This malware contains both a JavaScript injection component and a server-side backdoor.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top