#wordpress-exploitation

[ follow ]
Information security
fromThe Hacker News
21 hours ago

GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites

GootLoader has resurfaced, using custom WOFF2 glyph substitution and WordPress comment endpoints to deliver XOR-encrypted ZIP payloads, enabling rapid domain controller compromise and ransomware hand-offs.
[ Load more ]