WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
A widespread phishing campaign that targets WooCommerce customers by posing as a security alert and asking them to download a "critical patch" but really deploying a backdoor is being warned about by cybersecurity researchers.
The activity, according to WordPress security firm Patchstack, was clever and a variation of a different operation that was noticed in December 2023 and used a phony CVE trick to compromise websites using the well-known content management system (CMS).
The most recent attack wave is thought to be either the work of the same threat actor or a new cluster that closely resembles the previous one due to the similarities in the phishing email lures, the fake websites, and the identical techniques used to hide the malware read more about WooCommerce Users Targeted b...


