Articles

These aren't thought pieces or recycled CVE summaries. Every article here documents a real incident — a compromise I investigated, a backdoor I hunted, a botnet campaign I mapped from first packet to final remediation. The source material is raw: actual access logs, live database dumps, captured HTTP headers, malware samples pulled directly from production servers, and forensic timelines reconstructed from evidence, not theory. Each case represents a real client, a real attack, and a real outcome. Names and identifying details are always protected. The technical depth is never sanitized. If you run infrastructure that matters, these are the exact threats operating against servers like yours right now.

Terminal installing a package, representing a dropper that installs a hidden web file manager

The Folder That Beat WordPress: How Gambling Spam Hijacked a Contact Page and Survived a Rebuild

Core was clean, the database was clean, the site had just been rebuilt, and the Contact page still served slot spam. The attacker never touched WordPress: they created a folder. How the hijack works, the hidden file manager behind it, and how to hunt it.

Read Article
Code on a laptop screen, representing a backdoor plugin and its command-and-control feed

The C2 That Hands You Tomorrow's Domain: Anatomy of a Supply-Chain ClickFix Backdoor

A four-hour CDN compromise installed a 3.8 KB plugin through admins' own browsers. Its payload URL lives on a rotating feed, a sibling turns the victim into a first-party proxy, and the loader steals tokens before anyone clicks. Full infrastructure and IOCs.

Read Article
Source code on a laptop screen in a dark room

The JPEG That Wasn't: A Compressed PHP Backdoor Disguised as an Image

It had a .jpg name and no image inside. A bzip2 archive hid an XOR-encrypted eval() backdoor that the scanner missed. Here is how to unpack it, hunt its loader, and prove the rest of the site is clean.

Read Article
A pirated software package hiding a backdoor

The Backdoor Came Pre-Installed: How a Nulled WordPress Theme Shipped Malware That Waited Two Years

Nobody broke in. The backdoor had been on the server for two years — installed on purpose, inside a pirated premium theme. Timestamp forensics proved where it really came from.

Read Article
Self-Healing WordPress Malware - 15 Persistence Layers

The Malware You Can't Kill: A 15-Layer Self-Healing Framework Is Sweeping Through WordPress Servers

You delete it. It comes back in seconds. A new breed of WordPress malware stores its full payload in the database, rebuilds from 15 independent persistence layers, uses blockchain for command-and-control, and upgrades itself to bypass your signatures — infecting 1,200+ sites in 10 days.

Read Article
SSO Signing Oracle - WordPress Plugin Authentication Bypass

The SSO Signing Oracle: How a WordPress Plugin's Own Authentication Became the Attack Vector

The server's scanner caught every payload. But the malware kept coming back. Six rotating IPs, zero credentials, and a management plugin's SSO endpoint that handed out admin access to anyone who called it — because step 1 was a signing oracle for step 2.

Read Article
Homoglyph Backdoors - Lookalike Filenames in WordPress Malware

Homoglyph Backdoors: How Attackers Hide Malware in Lookalike Filenames

The file was called singIe.php. It looked like single.php. It wasn't. A capital I hiding in plain sight was the only thing separating a WordPress template from a command-execution webshell — and the attacker deployed seven waves of them over two weeks.

Read Article
Caught Red-Handed - Real-Time Attacker Engagement

Caught Red-Handed: Fighting an Attacker in Real Time During a WordPress Cleanup

I deleted the backdoor. Sixty seconds later, new webshells appeared on a site I'd already cleaned. The attacker was still inside — watching us work, and re-deploying from a foothold we hadn't found yet.

Read Article
Dead Drop Data Exfiltration via JSONBin.io

Dead Drop: How Attackers Use JSONBin.io to Exfiltrate WordPress Credentials

The malware scanner flagged gambling spam. But buried in a fake plugin was something far worse: a modular exfiltration suite silently uploading passwords, database credentials, and environment variables to a public JSON API every hour.

Read Article
You Deleted the Crime Scene, Then Called the Detective

You Deleted the Crime Scene, Then Called the Detective

7 in 10 clients restore from backup or wipe malware files before the analyst even connects. They think they are helping. They are destroying everything that matters — and guaranteeing the attacker comes back.

Read Article
Joomla Helix3 Mass Defacement Campaign

50 Sites Defaced in 48 Hours: Inside the Joomla Helix3 Mass Exploitation Wave

The files were clean. The malware scanner found nothing. But every page loaded a full-screen skull overlay — because the payload lived in the database, injected through an unauthenticated AJAX handler that no one was watching.

Read Article
Go C2 Agent Disguised as Linux Kernel Thread

Ghost in the Process List: A Go C2 Agent Disguised as a Linux Kernel Thread

ps aux showed nothing unusual — just kernel threads. But one was a 5.6MB Go binary with HTTP/2, WebSocket tunneling, and encrypted C2 communication, deployed through a header-based webshell with a backdated timestamp.

Read Article
Global Honeypot Network - 11547 Spam Attacks

I Set 4 Traps Across 3 Continents. Here's What Crawled In.

4 honeypot servers. 3 continents. 12 AI agents running through the night. In 38 hours I logged 11,547 spam attempts from 872 unique IPs, fingerprinted 6 coordinated campaigns, and deployed a blocklist that cut client spam by 97.4% — before the next wave hit.

Read Article
ClickFix Blockchain C2 - Fake Cloudflare CAPTCHA

ClickFix on the Blockchain: How Attackers Use Smart Contracts to Deliver Fake Cloudflare CAPTCHAs

Every scanner said clean. No eval(), no base64_decode(). Just ob_start() rewriting every response — with the payload URL stored on a BSC testnet smart contract. Here's how a four-line wp-config.php injection evaded every detection tool.

Read Article
Phantom Admin - WordPress Backdoor That Hides Users

Phantom Admin: Inside a WordPress Backdoor That Hides Users and Rebuilds Itself

I ran wp user list. Three admins came back. SQL showed four. The invisible administrator was hidden by the same mu-plugin that rebuilds itself from a 97 KB database payload every time you delete it.

Read Article
Invisible Reverse Shells - gsocket Backdoors

Invisible Reverse Shells: How gsocket Backdoors Hide in Plain Sight

The crontab looked empty. The .profile had a system comment. The .bashrc seemed normal. All three were hiding gsocket reverse shells using ANSI escape codes that erase themselves from terminal output.

Read Article
MySQL Trigger Malware

When the Database Fights Back: MySQL Trigger Malware That Protects Itself

I cleaned the spam. The database undid it. Inside a 4-layer self-healing WordPress infection that uses MySQL triggers to block its own removal.

Read Article
Server-Side Magecart

Server-Side Magecart: How Attackers Steal Credit Cards Directly from Magento's PHP Checkout

Deep dive into a server-side credit card skimmer injected into Magento vendor checkout files, using multi-pass XOR encryption to silently exfiltrate payment data for 7 months.

Read Article
CosmicSting JFIF Evasion

CosmicSting & JFIF Evasion: How Magento Webshells Hide Inside Image Files

How attackers exploit CVE-2024-34102 to deploy PHP webshells disguised as JPEG images, evading scanners that filter by file extension.

Read Article
Self-Healing Malware

The Malware That Wouldn't Die: Self-Healing WordPress Backdoor

How a WordPress backdoor survives complete file deletion by storing its payload in the database and regenerating itself on every HTTP request.

Read Article
PHPUnit RCE Attack

Surge in PHPUnit RCE Attacks: What Honeypots Reveal

Analysis of the recent surge in CVE-2017-9841 exploitation attempts targeting PHPUnit's eval-stdin.php for remote code execution.

Read Article
WordPress Security

wp-compat.php: Malware Backdoor Plugin in WordPress

Analysis of a dangerous WordPress plugin that creates hidden admin users and maintains backdoor access.

Read Article
No articles match "". Try a different keyword.