SlashNext warns of PhishWP stealing personal data (Image Credit: Towfiqu barbhuiya on Unsplash)SlashNext is warning about PhishWP, a new WordPress plugin that is designed to steal personal payment data. It found the plugin on a Russian cybercrime forum during a regular search for malware. The malware creates a fake payment page and captures customer data. It even intercepts the one-time password (OTP) sent by a 3D Secure (3DS) check sent by a credit card company or bank.

Interception of the OTP is done through pop-ups that appear on the screen. It helps the attackers bypass authentication processes and gives them the key data required to carry out other attacks.

All the data, including the OTP, is sent immediately via Telegram to the cybercriminals. The attack is seamless and gives the customer little to no indication of there being anything wrong.

PhishWP can be installed on any WordPress site once it is compromised. Alternatively, cybercriminals can set up their own fake websites and install them there. The advert for the malware specifically says that it is a Stripe payment plugin for WordPress. However, it is likely that there are other versions for other payment plugins.

SlashNext warns of PhishWP stealing personal data (Image Credit: SlashNext)
PhishWP advert

What is especially worrying here is the low cost of the plugin. The advert for it says that it is just $1.40 to acquire. What is not clear is if that is a per-transaction price or a single one-off payment. If the latter, the returns to the buyer far outweigh the benefits to the developer.

Key Features of PhishWP

In its disclosure of PhishWP, SlashNext has listed seven key features of the malware:

  1. Customizable Checkout Pages: Simulates payment processors like Stripe, creating highly convincing fake interfaces.
  2. 3DS Code Harvesting: Tricks victims into entering one-time passwords (OTPs) via pop-ups, bypassing authentication layers.
  3. Telegram Integration: Instantly transmits stolen data to attackers for real-time exploitation.
  4. Browser Profiling: Captures details such as IP addresses, screen resolutions, and user agents to replicate user environments for future fraud.
  5. Auto-Response Emails: Sends fake order confirmations to victims, delaying suspicion and detection.
  6. Multi-Language Support: Enables global phishing campaigns by accommodating multiple languages.
  7. Obfuscation Options: Provides an obfuscated version of the plugin for stealth or source code for advanced customizations.

Enterprise Times: What does this mean?

PhishWP is a new tool designed to be deployed quickly and easily by cybercriminals. Its low cost will make it attractive to anyone who wants to harvest payment details. The acquisition of the OTP and other data will allow attackers to make purchases using the customer data or sell the bundle of data to other people.

From the information provided by SlashNext, it will be difficult, if not impossible, for users to spot the malware. The problem is that it appears seamless and can be customised to keep it up to date with any changes made by payment processors such as Stripe.

The company says that its Browser Phishing Protection will detect malware. Whether other security products will detect it is not clear. At the time of writing, no other security vendor has mentioned the threat from PhishWP. Now it is known, expect other tool vendors to do more to detect it.

The main onus for protection, however, should be on those site owners who take payments through their websites. They need to make sure that they have proper security tools and processes in place to stop the installation of malicious plugins like this.

Previous articleDigital Edge raises $1.6bn for data centre expansion
Next articleFloQast appoints John Phillips as EMEA leader
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here