WooCommerce admins targeted by fake security patches that hijack sites

A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a “critical patch” that adds a WordPress backdoor to the site.

Recipients that take the bait and download the update are actually installing a malicious plugin that creates a hidden admin account on their website, downloads web shell payloads, and maintains persistent access.

The campaign, which was discovered by Patchstack researchers, appears to be a continuation of a similar operation in late 2023 that targeted WordPress users with a fake patch for a made-up vulnerability.

Patchstack says both campaigns used an unusual set of web shells, identical payload hiding methods, and similar email content.

Fake security alert

The emails targeting WordPress admins spoof the popular WooCommerce e-commerce plugin, using the address ‘help@security-woocommerce[.]com.’

Recipients are informed that their websites were targeted by hackers attempting to exploit an ‘unauthenticated administrative access’ vulnerability.

To protect their online stores and data, recipients are advised to download a patch using the embedded button, with step-by-step instructions on how to install it included in the message.

“We are contacting you regarding a critical security vulnerability found in WooCommerce platform on April 14, 2025,” reads the phishing emails.

“Warning: Our latest security scan, carried out on April 21, 2025, has confirmed that this critical vulnerability directly impacts your website.”

“We strongly advise you to take urgent measures to secure your store and protect your data,” continues the email to add a sense of urgency.

Clicking on the ‘Download Patch’ button takes victims to a website that spoofs WooCommerce, using a very deceptive ‘woocommėrce[.]com’ domain that is only one character different from the official, woocommerce.com.

The malicious domain employs a homograph attack technique where the Lithuanian character “ė” (U+0117) is used instead of an “e,” making it easy to miss.

Post-infection activity

After the victim installs the fake security fix (“authbypass-update-31297-id.zip”), it creates a randomly named cronjob that runs every minute, attempting to create a new admin-level user.

Next, the plugin registers the infected site via an HTTP GET request to ‘woocommerce-services[.]com/wpapi,’ and fetches a second-stage obfuscated payload.

This, in turn, installs multiple PHP-based web shells under ‘wp-content/uploads/,’ including P.A.S.-Form, p0wny, and WSO.

Patchstack comments that these web shells allow full control of the site and could be used for ad injection, redirecting users to malicious destinations, enlisting the server to DDoS botnets, stealing payment card information, or executing ransomware to encrypt the site and extort the owner.

To evade detection, the plugin removes itself from the visible plugin list and also hides the malicious administrator account it created.

Patchstack advises website owners to scrutinize admin accounts for 8-character random names, unusual cronjobs, a folder named ‘authbypass-update,’ and outgoing requests to woocommerce-services[.]com, woocommerce-api[.]com, or woocommerce-help[.]com.

However, the security firm notes that threat actors typically change all these indicators once they’re exposed via public research, so make sure you don’t rely on narrow-scope scans.

https://www.bleepingcomputer.com/news/security/woocommerce-admins-targeted-by-fake-security-patches-that-hijack-sites/

The Complete Guide to Mastering Your Link & Navigation Structure

Learn the best practices that will help you build an efficient and user-friendly navigational structure for your ecommerce website.
One of the biggest breakdowns I see most often in website architecture is sites with poor navigation.

On a pure usability level, navigation has one job: help visitors find the information they need. But in reality, there is a lot more going on under the hood that makes a site navigation succeed (or fail).

Read more

Why should you migrate to the AWS Cloud with Dynamic Concepts today?

Why should you migrate to the AWS Cloud with Dynamic Concepts today?

  1. IMPROVE PERFORMANCE Provision the compute, storage, and memory you need to support even the most demanding workloads without hardware refreshes.
  2. AUTOMATE SCALING Set conditions that can automatically scale your capacity up and down to maintain availability and optimal resource utilization.
  3. USE THE SAME TOOLS AS ON-PREMISES Leverage existing virtual machine images and management software like Microsoft System Center and VMWare vCenter
  4. GAIN GLOBAL AVAILABILITY Access reliable, highperformance global IT infrastructure with a few clicks.
  5. SECURE YOUR DATA Protect data with 256-bit encryption, virtual isolation, identity and access controls, and more.
  6. CAPITALIZE ON PAY AS YOU GO PRICING Trade CapEx for OpEx and stop paying for resources that you don’t need.

How Attackers Gain Access to WordPress Sites

Research on March 23, 2016 by Dan Moen

On this blog we write a lot about different vulnerabilities that could lead to site compromise. In our Learning Center we go deep on a myriad of important topics related to WordPress security. Our handy checklist, for example, includes 42 items you really should be paying attention to. But surely not all 42 items are equally important, right? In today’s post we dive into some very interesting data we gathered a couple of weeks ago in a survey, letting the facts tell us what matters most.

Read more

5 ways your email could be at risk

dynamic-concepts-hosted-exchange-emailNearly all businesses rely on email to assist with day-to-day activities. But many businesses haven’t addressed new and seemingly unavoidable vulnerabilities. If you are running an Exchange server on-premises or if you lack certain email security capabilities, your email could be at risk.

Read more

Creative Technology. Brilliant Results!

Big or small, we’ve got a solution when you need it. Our advanced service and support tools provide you with great customer service. Contact us today to learn more about Dynamic Concepts creative technology tools.