WordPress malware campaign hides payloads in Steam profiles
A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payloads, bypassing traditional detection methods and leveraging Valve's platform for C2. This campaign highlights the evolving tactics of threat actors and the importance of robust website security measures.
The campaign, initially discovered in July 2025, involved GoDaddy security engineers identifying malware on approximately 1,980 WordPress sites. The core of the attack relies on exploiting Steam Community profiles to conceal C2 communication. Attackers embed malicious scripts within seemingly innocuous comments, using invisible Unicode characters to encode the payload. This technique allows them to avoid detection by traditional security tools that may not recognize the hidden data. The initial infection vector is believed to be a combination of stolen credentials, vulnerable themes/plugins, or a supply-chain compromise.