WordPress sites targeted by a malicious plugin disguised as a safety tool


  • Wordfence researchers discover new WordPress malware
  • Threat actors used AI to create legitimate appearance tools
  • Malware claims to be an anti-malware product

Security researchers have discovered WordPress malware pretending to be an anti-logicial solution. At the end of April, Marko Wotschka of the WordFence team published a new blog detailing an “interesting WordPress malware”: it appears in the normal WordPress plugin, often with the name “WP-Antymalwary-Bot.php”.

While looking discreet at first, the researchers discovered that this plugin contains several functions which allows attackers to persist on the target website, hide the plugin on the dashboard and execute the code remotely.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top