New PhishWP Plugin on Russian Forum Turns Sites into Phishing Pages
by Fringustavo - Monday January 6, 2025 at 10:19 PM
#1
New PhishWP Plugin on Russian Forum Turns Sites into Phishing Pages

A recent report by SlashNext reveals that Russian cybercriminals have developed a malicious WordPress plugin named PhishWP. This plugin enables attackers to transform legitimate websites into phishing traps by creating convincing fake payment pages that mimic services like Stripe. These counterfeit pages deceive users into entering sensitive information, including credit card details, CVV codes, and 3D Secure one-time passwords (OTPs).

PhishWP boasts several advanced features that enhance its effectiveness:
Customizable Checkout Pages: Allows attackers to design fake payment interfaces that closely resemble legitimate ones.
3DS Code Harvesting: Tricks users into providing OTPs through deceptive pop-ups, effectively bypassing additional authentication layers.
Telegram Integration: Immediately transmits stolen data to attackers via Telegram, facilitating real-time exploitation or sale on the dark web.
Browser Profiling: Collects details such as IP addresses, screen resolutions, and user agents to tailor attacks to specific user environments.

The plugin’s multi-language support and obfuscation features enable cybercriminals to conduct targeted phishing campaigns on a global scale, leading to significant financial losses and personal data breaches.

To mitigate these risks, cybersecurity experts recommend implementing robust security measures, such as browser-based phishing protection tools, and maintaining vigilance during online transactions. Proactive security practices are essential to reduce vulnerability to these sophisticated attacks.

Source : https://hackread.com/phishwp-plugin-russ...ing-sites/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  New Crocodilus malware steals Android users’ crypto wallet keys KingDice 2 336 03-31-2025, 07:55 AM
Last Post: KingDice
  New OpenSSH flaws expose SSH servers to MiTM and DoS attacks KingDice 5 866 03-02-2025, 08:09 AM
Last Post: eVee
  Rapid7 Flags New PostgreSQL Zero-Day Connected to BeyondTrust Exploitation KingDice 1 592 02-20-2025, 11:56 AM
Last Post: ewxrbg
  Russian spies had access to EMA systems for four months in 2020 hack: report ewxrbg 0 477 02-20-2025, 11:44 AM
Last Post: ewxrbg
  New Zyxel Zero-Day Under Attack, No Patch Available KingDice 0 534 02-02-2025, 08:10 AM
Last Post: KingDice



 Users browsing this thread: 1 Guest(s)