A sophisticated cybercrime operation dubbed “DollyWay World Domination” has successfully infiltrated more than 20,000 WordPress websites since 2016, redirecting unsuspecting users to malicious destinations.
The attack, named after the distinctive code snippet define (‘DOLLY_WAY’, ‘World Domination’) found within the malware, continues to evolve with advanced evasion techniques that challenge traditional security measures.
Kaspersky reports that the DollyWay campaign primarily targets WordPress installations through vulnerable plugins and themes, capitalizing on the platform’s massive global footprint that powers nearly half of all websites worldwide.
Security researchers at GoDaddy first documented this extensive operation in March 2025, revealing that threat actors have maintained persistent access to compromised sites for nearly a decade.
The attack methodology employs a multi-stage approach beginning with the injection of seemingly benign scripts that bypass static HTML code analysis.
These initial payloads function as digital trojans, establishing persistent backdoors before downloading additional malicious components designed for victim profiling, command-and-control communications, and traffic redirection operations.
The malware demonstrates remarkable persistence through an advanced re-infection mechanism that triggers whenever any page on the compromised website loads, making complete remediation exceptionally challenging.
The DollyWay operators have developed a complex monetization strategy leveraging two primary affiliate networks: VexTrio and LosPollos.
VexTrio, described by cybersecurity experts as the “Uber of cybercrime,” serves as the primary traffic broker, directing victims to various scam websites, including fake dating platforms, cryptocurrency frauds, and illegal gambling operations based on detailed victim profiling data.
The campaign’s partnership with LosPollos adds legitimacy to some redirections, occasionally directing traffic to authentic applications like Tinder or TikTok on Google Play.
This dual-track approach not only generates revenue through both legitimate and illegitimate channels but also helps obscure the malicious nature of the overall operation by mixing fraudulent redirects with genuine app promotions.
DollyWay employs sophisticated concealment methods that significantly complicate detection and removal efforts.
The malware strategically injects malicious code across all active plugins simultaneously, requiring comprehensive cleanup across multiple components to prevent re-infection.
Additionally, the campaign creates unauthorized administrator accounts with elevated privileges while simultaneously hiding these accounts from the standard WordPress dashboard interface.
The operation includes credential harvesting capabilities through keylogger functionality that monitors administrative login forms, storing captured credentials in hidden files for future exploitation.
Researchers have also identified specialized maintenance scripts and web shells that enable remote management of infected infrastructure, including WordPress updates, component installations, and malware injection processes.
Most concerning is the campaign’s competitive protection mechanisms designed to prevent rival malware from infiltrating already compromised sites.
This incident suggests highly organized threat actors are committed to maintaining long-term access to their digital assets.
Organizations operating WordPress websites should conduct immediate security audits that focus on plugin and theme vulnerabilities, monitor file creation and deletion events as potential indicators of compromise, and consider deploying additional authentication layers, including two-factor authentication for administrative access.
Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…