Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse – Research Advisory

    June 1, 2026

    WordPress malware campaign hides payloads in Steam profiles

    June 1, 2026

    VU#158530: PCTCore64.sys Windows kernel driver contains missing access control vulnerability

    June 1, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»WordPress malware campaign hides payloads in Steam profiles
    News

    WordPress malware campaign hides payloads in Steam profiles

    adminBy adminJune 1, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    WordPress malware campaign hides payloads in Steam profiles

    Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data.

    The threat actor used invisible Unicode characters to encode a payload that builds a URL to a malicious script. By leveraging Valve’s platform, the attacker avoids maintaining a separate C2 infrastructure and evades traditional detection methods.

    Since the campaign was first uncovered in July 2025, GoDaddy security engineers have found malware on approximately 1,980 WordPress websites.

    image

    It is unclear how the hackers breach the websites, but researchers assess that the initial infection vector ranges from stolen admin logins or compromised FTP/SFTP credentials to the exploitation of a vulnerable WordPress theme or plugin, or a supply-chain compromise.

    The first-stage malware planted on a website uses WordPress page loads to reach specific Steam profiles and extract text from benign-looking comments.

    However, the text includes hidden Unicode characters that conceal malicious payloads sometimes disguised as ASCII art.

    Malicious Steam comment
    Malicious Steam comment
    Source: GoDaddy

    GoDaddy researchers note in a report that the threat actor uses six invisible Unicode characters for the encoded payload:

    • Zero-width non-joiner (U+200C)
    • Zero-width joiner (U+200D)
    • Function application (U+2061)
    • Invisible times (U+2062)
    • Invisible separator (U+2063)
    • Invisible plus (U+2064)

    The decoder ignores any visible character and maps the invisible ones to a corresponding number; then it converts them to binary representation and reconstructs bytes from the binary stream.

    “This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy says.

    According to the researchers, the decoded payload is used to build a hello-mywordl[.]info URL serving JavaScript code that is injected into every frontend WordPress page.

    Based on the file names (e.g., asahi-jquery-min-bundle and lodash.core.min.js), the retrieved malware is disguised as a legitimate JavaScript library.

    The final stage of the attack is implementing a backdoor that responds to specially crafted POST requests that include a specific authentication cookie. If the “tEcaKKXEsb cookie is present, the backdoor accepts base64-encoded PHP code via POST parameter,” the researchers explain.

    POST request with the right cookie
    POST request with the right cookie
    Source: GoDaddy

    GoDaddy describes several evasion mechanisms employed by the malware, including obfuscated strings using octal and hex escapes, randomized function names, fake disabled logging code, and the use of standard WordPress APIs, allowing it to blend with normal activity.

    Site owners can defend by checking for references to Steam Community URLs, suspicious external JavaScript injections, outbound connections from WordPress servers to Steam, and unexpected scripts loading from domains such as hello-mywordl[.]info.

    Other indicators include invisible Unicode characters, suspicious _transient_caption_ cache entries, disabled SSL verification in cURL requests, and POST requests containing the malware’s authentication cookies or the new_code parameter.

    The researchers recommend that security teams prioritize restoring from a known good backup before the infection date. If this is not possible, the manual cleaning process should be thorough because “attackers can reinstall removed code through the backdoor if any component remains active.”


    article image

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleVU#158530: PCTCore64.sys Windows kernel driver contains missing access control vulnerability
    Next Article Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse – Research Advisory
    admin
    • Website

    Related Posts

    News

    Microsoft investigates Office Apps, Teams file access issues

    June 1, 2026
    News

    InfoSec News Nuggets — June 1, 2026 – AboutDFIR

    June 1, 2026
    News

    Microsoft fixes KB5089549 Windows security update install issues

    June 1, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse – Research Advisory

    June 1, 2026

    WordPress malware campaign hides payloads in Steam profiles

    June 1, 2026

    VU#158530: PCTCore64.sys Windows kernel driver contains missing access control vulnerability

    June 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.