The NCSC warns about a WordPress botnet that not only targets websites, but also pulls visitors into the attack scenario. Cybercriminals misuse hacked or vulnerable WordPress sites to trick people with a fake update to their browser or other software. When visitors download and run such an “update,” it can lead to malware on the device and potentially the theft of login credentials.
During an international operation, the botnet SocGholish was taken down. That does not remove the need for precautions, however: site owners still need to check whether their WordPress site has been abused.
How the WordPress botnet tricks visitors
In practice, visitors are shown a message that looks like a legitimate update. For example, a pop-up such as: “Update Chrome/Edge”. The key difference is that the message does not come from the browser itself, and no real update is performed through the official route.
Instead, attackers ask users to download and open a file. Often it is a .zip or .js file. Once that file is launched, the malware can be installed quietly. In addition, criminals can use infostealers to collect data such as login credentials, financial information, email addresses, and system information.
What can go wrong on your device
If the attack succeeds, criminals can then cause various types of damage. The NCSC mentions, among other things, that malware may be installed on the system, including scenarios such as ransomware.
Reputational damage can also occur for the compromised WordPress site. Not only do visitors face risks; the organization behind the website also suffers the consequences if the site is used to trick people.
Check your WordPress site if you’re an administrator
Are you the owner or administrator of a WordPress site? Then it’s wise to carry out targeted checks for signs of misuse. The NCSC provides a set of concrete actions you can take.
- Check admin accounts for names that begin with wp-maintenance or wp-backup. If you did not create accounts like these yourself, it can be an indication of infection.
- Enable multi-factor authentication (MFA/2FA) for administrators. Also secure the admin email address with MFA.
- Limit access to /wp-admin with IP allowlisting where possible.
- Reduce the number of administrators to the minimum necessary.
- Use strong, unique passwords, preferably via a password manager.
- Turn on alerts for exceptional actions, such as theme/plugin installations and role changes.
- Enable logging for changes and login attempts.
- Consider a WAF or a WordPress firewall to block suspicious requests.
- Block execution of PHP files in wp-content/uploads.
- Keep WordPress, plugins, and themes up to date and remove unused components.
- Install plugins and themes only from reliable sources.
- If you don’t use it, disable WordPress’s built-in file editing.
- Ensure good backups stored on a system other than the same web server.
- Use monitoring (malware scans and file integrity checks) so unexpected changes are noticed quickly.
If you suspect your site is being abused, the NCSC advises setting the website temporarily into maintenance mode. Restore from a clean backup if possible, update the system, and change all passwords.
As a visitor, recognize a fake update
Even if you’re not an administrator, you can prevent a lot of damage. The most important thing is awareness: on a compromised WordPress site, a fake notification may be shown that looks like a real update.
Watch out for these points:
- Don’t download anything and don’t open files you download.
- Close the tab or browser, and update only via the official browser settings.
- Have a full virus scan run and remove any suspicious downloads.
- Don’t disable your antivirus scanner to install a program.
- Log out of all active sessions of important accounts so any possibly stolen sessions are invalidated.
- Change passwords for critical accounts (such as email, work, and banking), preferably from a clean environment.
- Enable MFA/2FA where possible and use strong, unique passwords.
- Don’t save passwords in your browser.
- If you use a company or work device and you’re unsure, report it to your IT/security partner.
To check the browser update route, the NCSC states that you should do so within the official browser settings—e.g., in Microsoft Edge via Settings > About and in Google Chrome via Menu > Help > About.
What does Operation Endgame mean for you?
The takedown of SocGholish is part of Operation Endgame, which started in 2024 and is described as the largest international operation against ransomware and cybercrime. The NCSC works with the Police, the Public Prosecution Service (OM), and foreign authorities, with support from Europol and Eurojust, and involvement of private parties.
This approach helps, but the lesson remains the same: criminals can still misuse WordPress environments. That’s why it’s smart to get your security in order and to help visitors recognize fake updates.
In short: take action, both as an administrator and as a visitor
The NCSC warning shows that a WordPress botnet goes beyond hacking a site: visitors can be tricked into downloading and running harmful files. For administrators, this means checking for suspicious accounts, tightening access protection, and strengthening monitoring. For visitors, the key takeaway is: don’t trust an update notification on a website, don’t download anything, and update only through the official browser route.
Source: https://www.ncsc.nl/alerts/wordpress-sites-doelwit-van-botnet-bezoekers-ook-geraakt
