Steam as command center: the attack that infected almost 2,000 WordPress sites with invisible comments and backdoors

Author: Published 4 min de lectura 160 reading

The images in this article were generated with artificial intelligence. How we publish

A campaign since July 2025 has affected close to 1.980 WordPress sites, according to the analysis published by GoDaddy's security teams, and stands out for the creative use of a public platform to hide its command center (C2). Instead of raising own servers and exposing themselves to detection, attackers hide instructions within comments on Steam community profiles and then cause the malicious code on the compromised websites to read and decode those comments to build the URL from which to download harmful scripts.

The technique is based on invisible Unicode characters - among them variants of zero-wide and other non-printable symbols - interspersed in innocuous text that serves as camouflage. The decoder housed in the affected site ignores visible letters, maps those invisible marks to numbers, generates a binary sequence and reconstructs bytes that make up the remote direction of the malicious code. The final result is the JavaScript load that is impersonated as legitimate libraries and which, in turn, establishes a persistent mechanism and a backdoor in PHP.

Steam as command center: the attack that infected almost 2,000 WordPress sites with invisible comments and backdoors
Image generated with IA.

The backdoor described by GoDaddy accepts POST requests authenticated by a specific cookie and can run PHP code encoded in base64; in addition, operators use additional camouflage techniques such as random function names, octal / hex escaped chains and the abuse of standard WordPress APIs to mix with legitimate traffic. All this reduces the signals that alert automated defenders and unprepared administrators.

Using a very popular third party service like Valve / Steam to transport C2 signals has important implications: on the one hand, it makes it difficult for scanners based on black lists to detect communications because Steam's infrastructure is legitimate and massive; on the other, it facilitates the survival of the attacker because it avoids the need to maintain its own infrastructure. To better understand the area used by the attackers, see the Steam community page on steamcommunity.com and for the technical report on response and mitigation refer directly to the analysis published by GoDaddy in GoDaddy Security.

For WordPress site administrators the main and most secure recommendation is restore from a well known backup prior to intrusion. If this is not feasible, manually cleaning requires extreme completeness: you need to search and remove any backdoor that accepts reimplantations, rotate all credentials (administration panels, FTP / SFTP, databases, tokens API), force key renewal, enable multifactor authentication and review file and user permissions. It is also appropriate to block at the network level outgoing connections to campaign-related domains (e.g. hello-mywordl [.] info, identified by researchers) and to monitor requests with suspicious parameters such as the use of a new _ code parameter or the presence of the control cookie.

Steam as command center: the attack that infected almost 2,000 WordPress sites with invisible comments and backdoors
Image generated with IA.

In preventive terms it is crucial to reduce the attack surface: keep WordPress, up-to-date issues and supplements; remove plugins and unused issues; minimize accounts with administrative privileges; use a WAF and file integrity monitoring; and apply robust authentication policies and periodic password rotation. The official guide to hardening WordPress offers practical and recommended measures by the project itself at wordpress.org, and must be a starting point for any site manager.

In the operational plane, there are simple search indicators that help detect infections: references to Steam URLs in the code, external JavaScript injections on front-end pages, anomalous cache entries (for example related to _ transit _ capture _), cURL checks with disable SSL verification and POST request records including control cookie or coded payloads. However, due to the evasion and persistence of these devices, have a professional response or assistance from the hosting provider It is usually the most solid option when manual cleaning exceeds internal capabilities.

The attack shows how malicious actors combine old techniques (credental stuffing, vulnerable plugins or supply chain commitments) with creative C2 channel engineering. For security officials this confirms a recurring lesson: the visibility of outgoing communications and the hygiene of credentials are as important as perimetral defenses; ignoring them leaves the door open to threats that hide where it is least expected.

Coverage

Related

More news on the same subject.