WP-antymalwary-bot.php is a malicious WordPress plugin masquerading as security software and observed in an active campaign targeting WordPress sites. Reported by Wordfence and first discovered during a site cleanup effort in late January 2025, the malware is designed to maintain attacker access, hide itself from the WordPress admin dashboard, and enable remote code execution. Once installed and activated, it grants attackers administrator-level access to the WordPress dashboard and uses the WordPress REST API to facilitate remote code execution. The plugin also includes functionality to ping a command-and-control server, spread into other directories, inject malicious PHP into a site theme’s header file, and clear caches of popular WordPress caching plugins. Researchers observed that newer variants changed injection behavior by fetching JavaScript from another compromised domain, which is then used to serve ads or spam on compromised sites. Persistence is provided by an accompanying malicious wp-cron.php file that recreates and reactivates the malware on the next site visit if the plugin is removed. Additional filenames associated with variants include addons.php, wpconsole.php, wp-performance-booster.php, and scr.php. The initial infection vector is currently not known. The campaign has not been attributed to a specific threat actor, but Russian-language comments and messages in the code suggest the operators are likely Russian-speaking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WP-antymalwary-bot.php is a malicious WordPress plugin that provides attackers with admin access and remote code execution, is resilient to removal, and can spread to other directories. It is linked to Russian-speaking threat actors.
Malware disguised as a WordPress security plugin that provides persistent administrator access, hides itself, executes remote code, spreads to other directories, and injects malicious JavaScript for ad serving.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.