The DollyWay malware primarily targets WordPress sites, leveraging a network of compromised sites to redirect visitors to scam pages through traffic broker networks. It injects redirect scripts into sites using files like wp-content/counts.php. These nodes act as central command centers, providing the malware with the latest settings and ensuring the persistence of the infection. DollyWay also updates WordPress and removes competing malware to maintain control over compromised sites. The persistence and sophistication of the DollyWay campaign underscore the importance of continuous security monitoring and proactive measures to protect WordPress sites from such threats. This operation is notable for its advanced techniques in maintaining control over infected sites and its sophisticated methods of injecting malware. One such operation is “DollyWay,” a long-running campaign that has compromised over 20,000 WordPress sites globally. DollyWay v3 utilizes a distributed network of C2 and TDS nodes hosted on compromised WordPress sites. In addition to its sophisticated reinfection mechanisms, DollyWay injects backdoors into compromised sites. Such advanced techniques highlight the evolving nature of the DollyWay operation, which has adapted over nearly a decade to remain effective in the face of evolving security practices. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The operation is tied to VexTrio, a major cybercriminal affiliate network known for using DNS techniques and domain generation algorithms. The malware also maintains persistence by disabling security plugins and reinstalling itself every time a page is loaded. GoDaddy analysts noted that this reinfection process involves randomizing code to evade detection, making removal challenging without taking the site offline.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Mar 2025 08:35:07 +0000