The images in this article were generated with artificial intelligence. How we publish
A campaign since July 2025 has affected close to 1.980 WordPress sites, according to the analysis published by GoDaddy's security teams, and stands out for the creative use of a public platform to hide its command center (C2). Instead of raising own servers and exposing themselves to detection, attackers hide instructions within comments on Steam community profiles and then cause the malicious code on the compromised websites to read and decode those comments to build the URL from which to download harmful scripts.
The technique is based on invisible Unicode characters - among them variants of zero-wide and other non-printable symbols - interspersed in innocuous text that serves as camouflage. The decoder housed in the affected site ignores visible letters, maps those invisible marks to numbers, generates a binary sequence and reconstructs bytes that make up the remote direction of the malicious code. The final result is the JavaScript load that is impersonated as legitimate libraries and which, in turn, establishes a persistent mechanism and a backdoor in PHP.

The backdoor described by GoDaddy accepts POST requests authenticated by a specific cookie and can run PHP code encoded in base64; in addition, operators use additional camouflage techniques such as random function names, octal / hex escaped chains and the abuse of standard WordPress APIs to mix with legitimate traffic. All this reduces the signals that alert automated defenders and unprepared administrators.
Using a very popular third party service like Valve / Steam to transport C2 signals has important implications: on the one hand, it makes it difficult for scanners based on black lists to detect communications because Steam's infrastructure is legitimate and massive; on the other, it facilitates the survival of the attacker because it avoids the need to maintain its own infrastructure. To better understand the area used by the attackers, see the Steam community page on steamcommunity.com and for the technical report on response and mitigation refer directly to the analysis published by GoDaddy in GoDaddy Security.
For WordPress site administrators the main and most secure recommendation is restore from a well known backup prior to intrusion. If this is not feasible, manually cleaning requires extreme completeness: you need to search and remove any backdoor that accepts reimplantations, rotate all credentials (administration panels, FTP / SFTP, databases, tokens API), force key renewal, enable multifactor authentication and review file and user permissions. It is also appropriate to block at the network level outgoing connections to campaign-related domains (e.g. hello-mywordl [.] info, identified by researchers) and to monitor requests with suspicious parameters such as the use of a new _ code parameter or the presence of the control cookie.

In preventive terms it is crucial to reduce the attack surface: keep WordPress, up-to-date issues and supplements; remove plugins and unused issues; minimize accounts with administrative privileges; use a WAF and file integrity monitoring; and apply robust authentication policies and periodic password rotation. The official guide to hardening WordPress offers practical and recommended measures by the project itself at wordpress.org, and must be a starting point for any site manager.
In the operational plane, there are simple search indicators that help detect infections: references to Steam URLs in the code, external JavaScript injections on front-end pages, anomalous cache entries (for example related to _ transit _ capture _), cURL checks with disable SSL verification and POST request records including control cookie or coded payloads. However, due to the evasion and persistence of these devices, have a professional response or assistance from the hosting provider It is usually the most solid option when manual cleaning exceeds internal capabilities.
The attack shows how malicious actors combine old techniques (credental stuffing, vulnerable plugins or supply chain commitments) with creative C2 channel engineering. For security officials this confirms a recurring lesson: the visibility of outgoing communications and the hygiene of credentials are as important as perimetral defenses; ignoring them leaves the door open to threats that hide where it is least expected.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...