WooCommerce phishing campaign uses fake patch to lure victims into installing backdoors




  • Patchstack spotted a new phishing campaign targeting WooCommerce users
  • The email warns the users about a “critical vulnerability” that must be fixed
  • The “fix” is actually malware that creates a rogue admin account and drops stage-two malware

If you are a WooCommerce user, pay attention, since there is a new phishing campaign going around targeting people like yourself.

Recently, security researchers from Patchstack spotted a new phishing attack, which they described as “large-scale” and “sophisticated”. In the attack, the crooks would send an email, warning their targets about a critical vulnerability in their websites that needs to be addressed immediately.

https://cdn.mos.cms.futurecdn.net/Yae4hnKPo7wj7N2KXRVyWk.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img