Backdoor
BdThemes Supply Chain Attack: Poisoned JSON Feed Creates Rogue WordPress Admins Without Touching a Single Plugin File
Attackers compromised BdThemes' vendor infrastructure and poisoned a promotional-banner JSON feed served to 100,000+ WordPress sites, hijacking admin sessions to plant rogue accounts and a persistent webshell — no plugin update required.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.
SleeperGem: Hijacked Dormant RubyGems Accounts Drop a Persistent Backdoor on Developer Machines
Researchers disclose SleeperGem, a RubyGems supply-chain attack that hijacked long-dormant maintainer accounts to publish trojanized gems whose loader specifically targets developer workstations while evading CI runners.
OptinMonster CDN Supply-Chain Attack: Tampered SDK Backdoors WordPress Admins
Attackers stole an Awesome Motive CDN key and laced the OptinMonster, TrustPulse, and PushEngage SDKs with code that creates rogue admins and plants a web shell — on up to 1.2M fully-patched sites.
DAEMON Tools Supply Chain Compromise: Signed Installers Backdoored Since April 8, Chinese Actor Suspected
Trojanized DAEMON Tools Lite installers signed with the legitimate vendor certificate distributed a multi-protocol backdoor for nearly a month. Kaspersky telemetry shows infection attempts in 100+ countries, with a second-stage implant on government and scientific targets in Russia, Belarus, and Thailand.
DEEP#DOOR: Python Backdoor Hides C2 Behind bore.pub Tunneling Service to Steal Cloud and Browser Credentials
Securonix details DEEP#DOOR, a Python backdoor that uses the public bore.pub TCP tunneling service for C2, disables Defender/SmartScreen via batch loader, and harvests browser-stored cloud credentials from compromised hosts.
Smart Slider 3 Pro Update Infrastructure Compromised — Backdoored Build Pushed to 800K+ WordPress Sites
Attackers compromised Nextend's update servers to distribute a weaponized Smart Slider 3 Pro build containing a multi-layered RAT with credential exfiltration and persistent backdoors.