A sophisticated phishing campaign is targeting WordPress administrators with fake domain renewal emails that closely mimic legitimate WordPress.com notifications. The emails use urgency tactics and a professional appearance to convince recipients to act quickly, redirecting them to a fraudulent payment portal that replicates the official WordPress checkout interface. Victims are prompted to enter sensitive credit card details and two-factor authentication codes, which are then harvested and transmitted to attackers via Telegram messaging channels. The phishing infrastructure, including the fake payment page hosted at soyfix[.]com/log/log/, was identified and analyzed by independent security researchers, revealing a multi-stage attack designed to maximize the value of each compromised account.
The phishing portal collects cardholder information through a JavaScript form and immediately forwards the stolen data to the attackers. The campaign's generic approach, such as omitting specific domain names in the renewal notices, allows it to target a broad range of organizations and individuals. Security analysts warn that the convincing design and use of legitimate branding make these emails difficult to distinguish from authentic communications, increasing the risk of successful compromise among WordPress site administrators. Organizations are advised to scrutinize renewal notices and verify payment requests through official channels to avoid falling victim to this ongoing threat.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis by security researcher Anurag Gawande detailed that the phishing kit steals credit card information and SMS one-time passcodes, then exfiltrates the data through Telegram bots. The research also identified campaign infrastructure including soyfix[.]com and use of Alibaba Cloud SMTP services.
A phishing campaign emerged that impersonates WordPress.com domain renewal notices to trick WordPress administrators into visiting a fraudulent payment portal. The operation uses spoofed email delivery and urgency-themed lures to harvest payment data from victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.