Security News > 2022 > December > New GoTrim botnet brute forces WordPress site admin accounts

New GoTrim botnet brute forces WordPress site admin accounts
2022-12-13 17:27

A new Go-based botnet malware named 'GoTrim' is scanning the web for self-hosted WordPress websites and attempting to brute force the administrator's password and take control of the site.

The malware then connects to each site and attempts to brute-force the admin accounts using the inputted credentials.

If successful, GoTrim logs in on the breached site and reports the new infection to the command and control server, including a bot ID in the form of a newly generated MD5 hash.

To evade detection by the WordPress security team, GoTrim will not target sites hosted on Wordpress.com and instead only target self-hosted sites.

Finally, if the targeted WordPress site uses a CAPTCHA plugin to stop bots, the malware detects it and loads the corresponding solver.

To mitigate the GoTrim threat, WordPress site owners should use strong administrator account passwords that are hard to brute-force or use a 2FA plugin.


News URL

https://www.bleepingcomputer.com/news/security/new-gotrim-botnet-brute-forces-wordpress-site-admin-accounts/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159