Credit Card Skimmer and Backdoor on WordPress E-commerce Site

March 17, 2025, 10:08 a.m.

Description

A sophisticated malware attack targeting WordPress WooCommerce sites was discovered, involving multiple components: a credit card skimmer, a hidden backdoor file manager, and a reconnaissance script. The attack focused on financial gain and long-term control. The skimmer, injected into the checkout page, collected payment and billing information, sending it to a malicious server. A PHP backdoor allowed remote system command execution, while a reconnaissance script gathered server information. The attack demonstrates the evolving complexity of e-commerce platform threats, emphasizing the need for strict security measures, regular scans, proper access controls, and timely updates to prevent such exploits.

Date

  • Created: March 15, 2025, 7:22 a.m.
  • Published: March 15, 2025, 7:22 a.m.
  • Modified: March 17, 2025, 10:08 a.m.

Additional Informations

  • Retail