Half the Checkouts, Once a Month: A Magento Card Skimmer Hidden Inside require.js
A Magento skimmer appended to require.js in pub/static, shown only at checkout to half of visitors, plus GIF/PHP injectors that expire after 180 seconds.
Read ArticleI clean hacked WordPress, Magento, Joomla and OpenCart websites: malware removal, backdoor hunting and incident response for site owners, web agencies and hosting providers. Most cleanups are completed within 24 hours and every job ends with a written findings report.
A Magento skimmer appended to require.js in pub/static, shown only at checkout to half of visitors, plus GIF/PHP injectors that expire after 180 seconds.
Read ArticleA fake WordPress plugin showed a fake Cloudflare check to every visitor except admins, then kept serving it from cache after deletion. How to find and purge it.
Read ArticleCore was clean, the database was clean, the site had just been rebuilt, and the Contact page still served slot spam. The attacker never touched WordPress: they created a folder. How the hijack works, the hidden file manager behind it, and how to hunt it.
Read ArticleKKAA Solutions is a specialised cybersecurity and website malware remediation company founded by Konstantinos K. Bourdakos in Athens, Greece. I detect, analyse and remove malware from hacked websites and servers, and document every incident in a written report.
Athens, Greece
KKAA Solutions (Κ. ΜΠΟΥΡΔΑΚΟΣ & ΣΙΑ Ε.Ε.)
ΑΦΜ/VAT ID: 801985029
ΓΕΜΗ/GEMI: 167601003000
CloudLinux
I specialize in identifying, analyzing, and mitigating threats in server environments. My role focuses on ensuring system security by detecting malicious activities, removing malware, and implementing robust preventive measures.
Leveraging cutting-edge tools and techniques, I work to safeguard web hosting platforms and enterprise environments against evolving cyber threats.
KKAA Solutions (Κ. ΜΠΟΥΡΔΑΚΟΣ & ΣΙΑ Ε.Ε.)
Registered malware remediation and incident response consultancy serving hosting providers, digital agencies and site owners worldwide. On-demand forensic cleanup of compromised web servers — root cause analysis, backdoor hunting, database inspection, and evidence-backed reporting.
team.blue Group of Companies
Applying state of the art Web Hosting technologies while ensuring the deliverability of our services in a client oriented ecosystem.
CloudLinux
Providing consulting services of technical support for Imunify360 security products, a next-generation security solution built for Linux servers.
OTE Group of Companies (HTO)
System Administration & Operations of Hellenic Telecommunications Organization SA as part of Deutsche Telekom Group Of Companies. Accounts Involved t-Albania, t-Romania, TMNL, Coca-Cola & OTE Core.
KBourdakos Computer Systems
Duties Involved: Building OEM Systems, Contracts of Support, Sales/Retail, Imports/Exports (EU/USA), In-House Custom App Development, Web Hosting, Customer Support.
Piraeus University of Applied Sciences
University of Cambridge
Queen Mary's College, Basingstoke
These aren't thought pieces or recycled CVE summaries. Every article here documents a real incident — a compromise I investigated, a backdoor I hunted, a botnet campaign I mapped from first packet to final remediation. The source material is raw: actual access logs, live database dumps, captured HTTP headers, malware samples pulled directly from production servers, and forensic timelines reconstructed from evidence, not theory. Each case represents a real client, a real attack, and a real outcome. Names and identifying details are always protected. The technical depth is never sanitized. If you run infrastructure that matters, these are the exact threats operating against servers like yours right now.
A Magento skimmer appended to require.js in pub/static, shown only at checkout to half of visitors, plus GIF/PHP injectors that expire after 180 seconds.
Read ArticleA fake WordPress plugin showed a fake Cloudflare check to every visitor except admins, then kept serving it from cache after deletion. How to find and purge it.
Read ArticleCore was clean, the database was clean, the site had just been rebuilt, and the Contact page still served slot spam. The attacker never touched WordPress: they created a folder. How the hijack works, the hidden file manager behind it, and how to hunt it.
Read ArticleA four-hour CDN compromise installed a 3.8 KB plugin through admins' own browsers. Its payload URL lives on a rotating feed, a sibling turns the victim into a first-party proxy, and the loader steals tokens before anyone clicks. Full infrastructure and IOCs.
Read ArticleIt had a .jpg name and no image inside. A bzip2 archive hid an XOR-encrypted eval() backdoor that the scanner missed. Here is how to unpack it, hunt its loader, and prove the rest of the site is clean.
Read ArticleNobody broke in. The backdoor had been on the server for two years — installed on purpose, inside a pirated premium theme. Timestamp forensics proved where it really came from.
Read ArticleYou delete it. It comes back in seconds. A new breed of WordPress malware stores its full payload in the database, rebuilds from 15 independent persistence layers, uses blockchain for command-and-control, and upgrades itself to bypass your signatures — infecting 1,200+ sites in 10 days.
Read ArticleThe server's scanner caught every payload. But the malware kept coming back. Six rotating IPs, zero credentials, and a management plugin's SSO endpoint that handed out admin access to anyone who called it — because step 1 was a signing oracle for step 2.
Read ArticleThe file was called singIe.php. It looked like single.php. It wasn't. A capital I hiding in plain sight was the only thing separating a WordPress template from a command-execution webshell — and the attacker deployed seven waves of them over two weeks.
Read Article
I deleted the backdoor. Sixty seconds later, new webshells appeared on a site I'd already cleaned. The attacker was still inside — watching us work, and re-deploying from a foothold we hadn't found yet.
Read ArticleThe malware scanner flagged gambling spam. But buried in a fake plugin was something far worse: a modular exfiltration suite silently uploading passwords, database credentials, and environment variables to a public JSON API every hour.
Read Article7 in 10 clients restore from backup or wipe malware files before the analyst even connects. They think they are helping. They are destroying everything that matters — and guaranteeing the attacker comes back.
Read ArticleThe files were clean. The malware scanner found nothing. But every page loaded a full-screen skull overlay — because the payload lived in the database, injected through an unauthenticated AJAX handler that no one was watching.
Read Articleps aux showed nothing unusual — just kernel threads. But one was a 5.6MB Go binary with HTTP/2, WebSocket tunneling, and encrypted C2 communication, deployed through a header-based webshell with a backdated timestamp.
Read Article4 honeypot servers. 3 continents. 12 AI agents running through the night. In 38 hours I logged 11,547 spam attempts from 872 unique IPs, fingerprinted 6 coordinated campaigns, and deployed a blocklist that cut client spam by 97.4% — before the next wave hit.
Read ArticleEvery scanner said clean. No eval(), no base64_decode(). Just ob_start() rewriting every response — with the payload URL stored on a BSC testnet smart contract. Here's how a four-line wp-config.php injection evaded every detection tool.
Read ArticleI ran wp user list. Three admins came back. SQL showed four. The invisible administrator was hidden by the same mu-plugin that rebuilds itself from a 97 KB database payload every time you delete it.
Read ArticleThe crontab looked empty. The .profile had a system comment. The .bashrc seemed normal. All three were hiding gsocket reverse shells using ANSI escape codes that erase themselves from terminal output.
Read ArticleI cleaned the spam. The database undid it. Inside a 4-layer self-healing WordPress infection that uses MySQL triggers to block its own removal.
Read ArticleDeep dive into a server-side credit card skimmer injected into Magento vendor checkout files, using multi-pass XOR encryption to silently exfiltrate payment data for 7 months.
Read ArticleHow attackers exploit CVE-2024-34102 to deploy PHP webshells disguised as JPEG images, evading scanners that filter by file extension.
Read ArticleHow a WordPress backdoor survives complete file deletion by storing its payload in the database and regenerating itself on every HTTP request.
Read Article
Analysis of the recent surge in CVE-2017-9841 exploitation attempts targeting PHPUnit's eval-stdin.php for remote code execution.
Read ArticleAnalysis of a dangerous WordPress plugin that creates hidden admin users and maintains backdoor access.
Read Article