GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure


GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure

Pierluigi Paganini
June 02, 2026

Malware on approximately 2,000 WordPress sites hid C2 instructions in Steam profile comments using invisible Unicode.

GoDaddy researchers spotted a command-and-control infrastructure for a malware campaign abusing Valve’s Steam gaming platform. The experts discovered malware on approximately 1,980 WordPress sites that fetches its instructions by reading Steam Community profile comments, where the actual payload is hidden using invisible Unicode characters embedded between visible text.

“GoDaddy Security researchers have analyzed malware that uses an unconventional approach to command and control: encoding malicious payloads for WordPress within Steam Community profile comments.” reads the report published by GoDaddy.

From the outside, the comments look like ASCII art. From the inside, they’re encoded instructions telling infected WordPress sites where to load malicious JavaScript from.

The encoding scheme uses six Unicode characters that have no visible representation: zero-width non-joiner, zero-width joiner, function application, invisible times, invisible separator, and invisible plus. The malware strips all visible characters from the Steam comment, maps each invisible character to a number between 0 and 5, converts those numbers to binary, reconstructs bytes from the binary stream, and applies a bitwise NOT operation to each byte.

“This encoding allows binary data to be embedded within normal-looking text.” states the report. “The visible characters serve as camouflage while the invisible characters carry the actual payload.”

In some variants, the decoded output is further protected with AES-256-CTR encryption, PBKDF2 key derivation with 10,000 iterations, and HMAC-SHA256 authentication.

The decoded payload builds a URL pointing to hello-mywordl[.]info, which serves a JavaScript file called lodash.core.min.js. That name is deliberate. It mimics a legitimate, widely used JavaScript library. The malware injects it into every WordPress frontend page via the wp_enqueue_scripts hook using the handle “asahi-jquery-min-bundle,” another name chosen to look like standard infrastructure.

“The script is loaded on every WordPress frontend page via the wp_enqueue_scripts hook.” states the report. “The handle name “asahi-jquery-min-bundle” and filename “lodash.core.min.js” mimic legitimate JavaScript libraries.” 

Anyone scanning a site for suspicious scripts would need to look past convincingly named files to find it.

The server-side component is more dangerous than the JavaScript injection. The malware installs a backdoor that listens on every WordPress page load and checks for two specific authentication cookies in incoming POST requests. The first cookie triggers a ping response that tells the attacker the backdoor is still active and returns a version identifier. The second cookie is the destructive one.

«When the tEcaKKXEsb cookie is present, the backdoor accepts base64-encoded PHP code via POST parameter.” states the analysis. “The file modification function searches recursively through plugin and theme directories.»

The attacker sends updated PHP code, and the backdoor searches every plugin and theme file for a marker string, then overwrites matching lines with the new code. This means a partial cleanup that removes the JavaScript injection but leaves the backdoor intact accomplishes almost nothing: the attacker just rewrites the code they want back into whichever file they choose.

The obfuscation runs several layers deep. All string constants in the malware use octal or hexadecimal escape sequences, so a text search for “steamcommunity.com” or “https://” won’t find them. Function and variable names look like random hex strings. There’s a non-functional logging system scattered throughout the code with a hardcoded $enabled = false variable that ensures the logging never actually executes. It exists purely to make the code look like legitimate, carefully written software to anyone scanning it quickly. The malware also uses standard WordPress API calls throughout, which makes behavioral detection harder because everything looks like normal plugin activity.

How the initial infection happens isn’t confirmed. The most likely vectors are stolen WordPress admin credentials, compromised FTP or SFTP access, a vulnerable plugin or theme, or a supply chain compromise. None of those are unusual. What is unusual is what happens after: a multi-stage attack that uses a globally trusted gaming platform as infrastructure, invisible text as data encoding, and a self-updating backdoor that can survive partial remediation.

Detection starts with specific indicators. Any outbound connections from a WordPress server to Steam Community URLs are suspicious. References to hello-mywordl[.]info in loaded scripts are a direct indicator. In PHP files, look for invisible Unicode character arrays containing U+200C, U+200D, or U+2061 through U+2064, or cryptographic functions like hash_pbkdf2 and openssl_decrypt with AES-256-CTR mode appearing in plugin or theme files.

On the network side, POST requests containing cookie names DEpjndDbNc or tEcaKKXEsb, or a POST parameter named new_code, indicate active backdoor use. If you find an infection, restore from a clean backup before the infection date if at all possible. If you can’t, the manual cleanup has to be complete, because the remote code rewriting capability means any component left behind can reinstall everything else.

“Cleanup should prioritize restoration from a known-clean backup predating the infection whenever possible. If backups are unavailable or unreliable, manual remediation requires searching for and removing malicious code from all plugin and theme files, clearing suspicious WordPress transients from the database, verifying that no malicious scripts remain enqueued, and updating WordPress core along with all plugins and themes to current versions.” concludes the report. “The remote code rewriting capability means partial cleanup may be insufficient—attackers can reinstall removed code through the backdoor if any component remains active.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, malware)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


What streaming platform do you think of when you hear the term “comfort shows?” There are plenty of great comfort shows over on Netflix, or maybe available with an HBO Max subscription. But for me, I always think of Peacock.

With a Peacock subscription, there are so many options for classic comfort shows that will no doubt make your day—and provide you with that comfy need that we all so desperately crave. Here are seven that you must check out.

The Office

A classic comedy

Dwight in The Office. Credit: NBC

I mean, you knew it was going to be on here, don’t lie.​​​​​​​

The Office was a nine-season sitcom that took the world by storm. Starring Steve Carell as Michael Scott, this iconic workplace comedy follows the professional and personal lives of workers at a paper company in Scranton, Pennsylvania.

I think The Office is a show that defines the word “comfort.” Anytime I ask people what they usually put on in the background, The Office is always the first choice because it’s easy to follow, has characters you want to root for, and is so freaking funny (even if some of those jokes have not aged well all these years later). It’s certainly worth a shot

Parks And Recreation

Amy Poehler is the best

Amy Poehler in Parks and Recreation speaking to a camera Credit: NBC

Another great comfort show that also happens to come from the same developer of the U.S. version of The Office (the wonderful Greg Daniels), Parks and Recreation is a sitcom mainly about Leslie Knope, a mid-level bureaucrat who is trying to improve her home in the fictional town of Pawnee, Indiana, in the Parks and Recreation department.

The series is extremely well-received and has some huge stars attached, including Amy Poehler, Aziz Ansari, Nick Offerman, Adam Scott, Chris Pratt, Aubrey Plaza, and more. With seven seasons and one hundred and twenty-six episodes, you’re in for a long binge.​​​​​​​

Brooklyn Nine-Nine

The laughs go on and on

b99.jpg
Andy dressed asAndy Samberg as Jake Peralta with his arm around Eva Longoria as Sophia Perez in Brooklyn Nine-Nine

Brooklyn Nine-Nine is one of those shows that I think everyone has seen at least one episode of, just because it’s so funny. The main premise of the series follows the lives of police officers, detectives, and others in a fictional police precinct in New York, specifically in Brooklyn.

This series was a hit for NBC, and while it did move to another streaming platform towards the end of its run, it is a beloved comedy perfect for a weekend of comfy watching. Not only that, but the stars—Andy Samberg, Terry Crews, and more—have some of the best chemistry out there and will, no doubt, make you laugh out loud.

Everybody Loves Raymond

Who doesn’t love an Italian Long Island-er?

Ray Romano in Everybody Loves Raymond Credit: CBS

You better believe I put Everybody Loves Raymond on here—because everyone loves it!

This late 1990s-early 2000s sitcom stars Ray Romano as Ray Barone, an Italian-American who lives on Long Island and has made it as a successful sports writer. It tells the story of his family and how he deals with the drama, juggling his wife, his neighbors, and more.​​​​​​​


The Simpsons on Disney+ on a 4K TV in a green living room.


The 5 Most Popular Comfort Shows and Where to Stream Them

Switch on these shows when you want to switch off.

I genuinely cannot think of another television show I have seen more often over the last couple of decades than this, and the number of reruns is astronomical. With nine seasons, Everybody Loves Raymond is the type of binge you don’t want to miss.​​​​​​​

Modern Family

A series anyone can relate to

Claire and Phil Dunphy in Modern Family Credit: ABC

Now this is my kind of comfort show. Modern Family—and all eleven of its seasons—is available to stream on Peacock.

This groundbreaking sitcom tells the stories of three diverse families in the suburbs of Los Angeles and how their lives intersect. But it’s so much more than that. The comedy is hysterical, and yet each episode finds a new way to tug at your heartstrings.

Not only that, but it’s also just a genuinely relatable show for modern-day parents, and I’m not just saying that because of the name. It touches on both funny topics and social issues, making it a really well-done series. There’s a reason why there were so many Emmys thrown at this series.

That ‘70s Show

So much smoke—and friends!

Topher Grace on That '70s Show. Credit: Fox

For some reason, That ‘70s Show was the series I was obsessed with as a kid. And honestly, it’s a vibe, even now. The series mainly follows six teenagers in Wisconsin between 1976 and 1979 as they come of age, experience growing pains, and learn to come into their own while also smoking the devil’s lettuce, if you know what I mean.

On a real note, That ‘70s Show is a hilarious series with great performances from Topher Grace, Mila Kunis, Ashton Kutcher, Wilmer Valderrama, and so many more. This series has been with me on my good days and bad, and while its little successor, That ‘90s Show, on Netflix is a fun one, nothing compares to the original. You’re missing out if haven’t had the chance to sit down and watch the whole show.

Saturday Night Live

Laughs and more

Bill Hader and Ben Affleck in Saturday Night Live Credit: NBC

OK, so hear me out.

I know, when it comes to comfort shows, we honestly do think sitcoms are cute, but I think Saturday Night Live falls into that category. Why? Because it’s one of those shows that you can put on in the background and just chill.

It’s not something that’s heavily serialized or has any real plot to follow. It’s just funny sketches and enjoyable music performances. That’s it. And with the number of seasons that are available to watch on Peacock, you can’t really get better than this.


Peacock is such a great subscription service, and honestly, it just makes me want to rewatch each of these awesome shows. What are you looking forward to watching on a comfy weekend?

peacock thumbnail

Subscription with ads

Yes, $8/month

Simultaneous streams

3




Source link