A WordPress mass-compromise campaign affecting hundreds of sites. The rogue must-use plugin registers a Service Worker in the visitor’s browser, which strips the site’s Content-Security-Policy header and injects a script that reads its payload from a smart contract on Base. The threat employs Service Worker persistence, EtherHiding on-chain payload delivery, fake reCAPTCHA, and ClickFix. It also adds a disguised polyglot file, mshta abuse, a fileless PowerShell stage, an image-hidden loader, and finally the Amatera password stealer.
The campaign’s design choice is to have no durable artifacts to act on, making it challenging for defenders. The threat operates as a ladder, with each rung built to defeat one specific defense. It starts with a compromised WordPress site, followed by a malicious Service Worker that survives site cleanup and strips CSP.[/subscribe_to_unlock_form]
A WordPress mass-compromise campaign affecting hundreds of sites. The rogue must-use plugin registers a Service Worker in the visitor’s browser, which strips the site’s Content-Security-Policy header and injects a script that reads its payload from a smart contract on Base. The threat employs Service Worker persistence, EtherHiding on-chain payload delivery, fake reCAPTCHA, and ClickFix. It also adds a disguised polyglot file, mshta abuse, a fileless PowerShell stage, an image-hidden loader, and finally the Amatera password stealer.
The campaign’s design choice is to have no durable artifacts to act on, making it challenging for defenders. The threat operates as a ladder, with each rung built to defeat one specific defense. It starts with a compromised WordPress site, followed by a malicious Service Worker that survives site cleanup and strips CSP.[emaillocker id="1283"]
The next layer involves a Base smart contract holding the payload (EtherHiding), a fake reCAPTCHA prompt, an MP3/HTA polyglot, a scheduled task and PowerShell stage, an Emmenhtal loader with steganographic image on a legitimate CDN, a reflective loader that never writes the payload to disk, and finally the Amatera password stealer calling home over DNS-over-HTTPS.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.003 | Phishing | Spearphishing via Service |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1203 | Exploitation for Client Execution | - |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Defence Evasion | T1070.004 | Indicator Removal | File Deletion |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Execution | E1204 | User Execution |
| Exfiltration | E1020 | Automated Exfiltration |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
The following reports contain further technical details:
[/emaillocker]