Massive Botnet Attacking WordPress Websites

Опубликовано: 12 Март 2026
на канале: QuickSilk
1,123
2

View the full blog post at: https://bit.ly/2UFWoUq

Recent news from the security world of WordPress is that a botnet of over 20,000 compromised WordPress websites is being used to attack other WordPress websites. These websites are slowly creeping through the web and compromising other sites, then adding those websites to its botnet numbers.

Let's start by saying this. There are probably bigger and more complex WordPress botnets out there. Typically, tracking these massive botnets is difficult, and, according to Defiant (who own WordFence):

"It would typically be very difficult to track the central C2 servers behind it all. We were fortunate, though, that the attacker made some mistakes in their implementation of the brute force scripts."
The +20,000 website botnet was found by security researchers at Defiant, and they published a report at WordFence.com. As it currently stands, many of the websites in this botnet are still active — though Defiant is working with law enforcement to curb them.

So, how does this botnet work?

The attacker is using a group of compromised websites to enlist other websites into the botnet. By adding the compromised sites to the botnet, the attacker can gather information, breach data, and continue to enlist more and more websites into its malicious campaign. Anyone who owns one of these websites would probably never notice that their website is being used to attack other websites.

So, what are these botnets doing?

The botnet is attempting to log into websites by spamming the sites with random usernames and passwords until it generates a correct combination.

The attack abuses WordPress's XML-RPC interface — xmlrpc.php — which allows users to remotely upload files to their WordPress site. Here's the problem: WordPress's XML-RPC setup doesn't restrict the number of API requests issued. That means that the attacker can brute force passwords all-day-long without getting locked out. At the same time, no one is going to be alerted of the requests unless they happen to be looking at their log.

So, how did the attacker build this massive botnet?

The zombie websites are controlled using four C2 servers. Luckily, some mistakes made by the attacker clued WordFence into the fact that these servers existed.

These four C2 servers send commands to the +20,000 WordPress websites via multiple proxy servers on the Best-Proxies.ru server. In a sense, this is a sophisticated operation. The attacker sends commands to servers that send commands to proxy servers that send commands to the infected website that sends commands to attack other websites.

How Do You Protect Yourself?

Protecting your website from these types of botnets is tough. The best way — though most time consuming — is to check your logs consistently and pay attention to news surrounding WordPress theme and plugin vulnerabilities. Though, to be fair, there are thousands of those yearly, so we understand why that might not be the most accessible solution.

You could also invest in cybersecurity elements, but you'll need a pretty expensive 3rd party setup to combat sophisticated botnet attacks.

We don't have a ton of good news for you in this department. As long as you use WordPress, you are going to be vulnerable to these types of attacks. There's no way to completely distance your website from core vulnerabilities.

View the full blog post at: https://bit.ly/2UFWoUq