Attacks against Sites Running a Vulnerable Version of File Manager Plugin

Security researchers recently reported a File Manager plugin vulnerability. Which initially endangered more than 700,000 WordPress sites. However, in a few days, the number of attacked sites reached 2.6 million.

Multiple Attackers Exploiting the File Manager Plugin Vulnerability

According to Wordfence (Defiant) researchers, multiple threat actors are to blame for these attacks, with two specific threat actors being the most successful in the exploits. It appears that these attackers are now password protecting vulnerable copies of a specific file, known as connector.minimal.php.

The most active of these attackers have been identified as “bajatax”. That has previously been stealing credentials from PrestaShop sites. The indicators of compromise the researchers discovered include simple files that contained the “bajatax” string. And modifications to the original vulnerable connector.minimal.php data. The latter line is designed to lock out all other potential attackers. The researchers’ discoveries point out that these files are being utilized by some of the most dynamic IPs deployed in the attacks.

Infected sites will have malicious code added to them. This code utilizes Telegram’s API to exfiltrate the credentials of all users logging into the compromised site. Also, the same principle is added to the user.php folder, which is a core WordPress file.

The second attacker exploiting the File Manager vulnerability with great success is dropping a specific infector, feoidasf4e0_index.php, with an MD5 hash of 6ea6623e8479a65e711124e77aa47e4c. And a backdoor inserted by this infector, Wordfence says in the official report. This attacker is also a password protecting the connector.mininal.php to attempt locking out other threat actors.

The researchers also outline that the backdoor used by this second actor has been in use for many years. However, multiple copies can be scattered across a single infected site, leading to persistence if no protection is present.

Furthermore, once the backdoors are successfully installed. The attacker is utilizing them to make more modifications to core WordPress files.

What should you do if you have been using a vulnerable version of the File Manager plugin?

The best security advice is to use a security tool to scan your site for malware. In case you discover that your site has been compromised by the attacks described in this article. You should consider cleaning your website before doing anything else.

If you are the owner of an e-commerce site, you should also contact all of your users. Letting them know that their credentials may have been compromised. You can also test the overall security of your website using the tips we provided in the article below:

Also Read How To Test Your WordPress Site Security

Researched and created by:
Krum Popov
Passionate web entrepreneur, has been crafting web projects since 2007. In 2020, he founded HTH.Guide — a visionary platform dedicated to streamlining the search for the perfect web hosting solution. Read more...
Technically reviewed by:
Metodi Ivanov
Seasoned web development expert with 8+ years of experience, including specialized knowledge in hosting environments. His expertise guarantees that the content meets the highest standards in accuracy and aligns seamlessly with hosting technologies. Read more...

Leave a Comment

Your email address will not be published. Required fields are marked *

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree
At HTH.Guide, we offer transparent web hosting reviews, ensuring independence from external influences. Our evaluations are unbiased as we apply strict and consistent standards to all reviews.
While we may earn affiliate commissions from some of the companies featured, these commissions do not compromise the integrity of our reviews or influence our rankings.
The affiliate earnings contribute to covering account acquisition, testing expenses, maintenance, and development of our website and internal systems.
Trust HTH.Guide for reliable hosting insights and sincerity.