Steam Community Profiles Abused as C2 Network in New WordPress Malware Infection Campaign



  • Malware hides payload in Steam community comments
  • WordPress Sites Used to Host Backdoors
  • Almost 2,000 sites compromised since July

GoDaddy security researchers found a bold new malware campaign that used comments made by Steam community accounts as command and control (C2) infrastructure.

Here’s how the attack plays out: Attackers would first find vulnerable WordPress websites, or those protected by weak credentials, and use them to host PHP malware somewhere in the site’s files. For example, the sample was found in the ‘functions.php’ file of a theme. This malware contains a JavaScript injection component and a server-side backdoor.

Leave a Comment

Your email address will not be published. Required fields are marked *