Sr. Malware Research Mgr @ GoDaddy / Sucuri Inc. | Web Malware Analysis | Reverse Eng | Passionate about protecting the Web | Tweets and Thoughts are my own
GoDaddy Security researchers detail the evolution of Help TDS. The malicious woocommerce_inputs WordPress plugin, developed between late 2024 & June 2025 and incorporating credential harvesting, geo-filtering & advanced evasion, is installed on 10k+ sites. https://t.co/9N0NvZg1wm
The malicious woocommerce_inputs WordPress plugin is tightly integrated with HelpTDS (known for tech support scams), utilizing its C2 servers (t[.]me/s/trafficredirect and pinkfels[.]shop) for geo-targeting, credential exfiltration, and automatic updates. https://t.co/M7dJ0Juduy
Our analysis of 70.8 million global website scans in 2024:
Top website malware: Balada Injector, SocGholish, Japanese SEO spam.
Top trend: Fake browser updates and captchas.
New threat: Web3 cryptodrainers on compromised sites.
At GoDaddy, our security efforts are geared not only to help protect our customers — but also to benefit the wider internet community.
Our Website Malware Threat Report summarizes common malware threats seen in the past year — from traffic systems to social engineering.
Wrapping up the series of posts about the "DollyWay World Domination" malware operation. This time documenting the timeline and evolution from Master134 in 2016 to the current DollyWay v3.
https://t.co/Vb6vgJb1UD
Inside the DollyWay malware operation:
In part II of the series, security researcher @unmaskparasites explores the DollyWay campaign's distributed C2/TDS nodes, revealing redirect partners and campaign statistics. https://t.co/5O2kriporB
In this second follow-up post about the DollyWay malware operation, I explore the distributed DollyWay TDS/C2 nodes: architecture, redirect partners, statistics and estimated reach of the campaign
https://t.co/sx3uC5ygHM
The first of 3 in our series of posts about the “DollyWay World Domination” malware operation.
The most recent campaign: DollyWay v3. 10,000+ infected sites that redirect visitors to VexTrio and tech support scam sites.
https://t.co/zkfKQsfIHa
Since the end of September ClickFix fake plugins started using .js that loads the ethers lib from CloudFlare instead of https://t.co/UaR47yVVgC. Thus a new hash https://t.co/n2g41b5dRQ
Re: https://t.co/Czc3oacJMa
My research on swarms of fake WordPress plugins used to inject ClickFix fake browser update malware into thousands of websites worldwide.
This time publishing on GoDaddy Engineering blog:
https://t.co/Czc3oacJMa
Malwoverview 6.0.0 has been released:
https://t.co/EwDKd2Vsez
All the work was done by the new contributor, my colleague Artur Marzano (@MacmodSec), who deserves all the credit, he put in a lot of effort and dedicated his time to the project. For my part, I only helped Artur with the edge cases and in evaluating all the changes.
This new version is a complete refactoring of the project, where each endpoint is in a separate module. In addition, the code is cleaner and without duplication, making it easier for other professionals to contribute.
To install the new version 6.0.0:
$ python -m pip install -U malwoverview
Additional information is available on the GitHub.
#malware #threathunting #threatinformation #infosec #informationsecurity #dfir
SocGholish operates through a series of deceptive and sophisticated tactics designed to trick users and evade detection.
Learn about the most common indicators of compromise and mitigation steps to protect your site.
#SocGholish#malware
https://t.co/xnfant0VjY
It's here: Sucuri's 2023 Hacked Website & Malware Threat Report.
Discover the latest trends and stats for website malware and compromised websites.
Kudos to our malware research team for their hard work and invaluable insights!
It has been 15 years since the domain https://t.co/6gLkHKCzkj was registered, back on Apr 24, 2009.
Today we're saying "Happy 15th Birthday, Sucuri!" and thanks to all our amazing customers! #Sucuri15Years
Here is to another amazing 15 years and more!: https://t.co/bkp6BjMly8
Incident Response has identified a fresh wave of SocGholish infections targeting #WordPress websites. Infected sites are found using legit WP plugins that have been tampered with to deliver SocGholish payloads. Research by @_jamsec.
https://t.co/av99wD9d5p
#SocGholish#Malware
SocGholish scripts injected at the bottom of functions.php files of WordPress themes:
https://t.co/5sdUi5Os7u
https://t.co/eagowTRPHi
https://t.co/INjwfjtlkC
https://t.co/vTpwAUoeg5