Threat hunts for WordPress
8 hunts covering WordPress, each with a hypothesis, the queries that test it and what the hunt cannot see.
8 hunts
-
highResearch by Microsoft
Star Blizzard RedFlick VHDX and SSH-based Malware Delivery
An adversary has gained initial access via phishing and is using the RedFlick technique to deliver a backdoor through VHDX-mounted scripts, SSH-based MSI downloads, and CPL-driven scheduled tasks.
5 query2 analytic1 checkpoint1 action2 taskdefense evasion · execution · initial access -
highResearch by Sekoia
Exvicy ClickFix Social Engineering and PowerShell Execution
An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.
4 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Sekoia
ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Sekoia
ErrTraffic Infrastructure and Delivery Monitoring
An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Rapid7
Metasploit Lateral Movement and Native Persistence
An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 1 of 2Research by Rapid7
Metasploit 2026: External Recon and Web Exploitation
An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-0265 · CVE-2026-16232 -
high Part 2 of 2Research by Microsoft
Storm-3168 Web Application Probing
An adversary is conducting automated web reconnaissance by probing for specific administrative and AI-related paths to identify vulnerable entry points for a subsequent cloud-focused intrusion.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 1 of 2Research by Microsoft
Storm-3168: Automated Azure Resource Destruction and Recovery Inhibition
A compromised service principal is executing an automated sequence of Azure resource discovery, mass deletion, and credential collection to facilitate a cloud-native ransomware operation.
4 query2 analytic1 checkpoint1 action2 taskcredential access · discovery · impact