Cyber Security News

Fake WordPress Domain Renewal Email Targeting Admins to Steal Credit Card Data

A deceptive phishing campaign is actively targeting WordPress administrators with convincing fake domain renewal notices designed to steal credit card information and two-factor authentication codes.

The emails, masquerading as legitimate WordPress.com renewal reminders, redirect unsuspecting victims to a fraudulent payment portal where sensitive financial data is immediately harvested and sent to attackers through Telegram messaging channels.

The attack begins with a well-crafted phishing email bearing the subject line “Renewal due soon – Action required.”

The message uses urgency-based tactics to pressure recipients into immediate action, warning of potential service disruption without specifying the actual domain name. This generic approach allows the campaign to cast a wide net across multiple organizations.

The email maintains a polished, professional appearance designed to bypass spam filters and appear credible to recipients who may not scrutinize the sender details closely enough.

Fake email (Source – Malwr-Analysis)

An independent security analyst, Anurag Gawande, identified the malware campaign after analyzing the phishing infrastructure. Upon investigation, Gawande discovered a sophisticated multi-stage attack designed to extract maximum value from each compromised account.

Victims clicking the email link are directed to a fake WordPress checkout page hosted on attacker infrastructure at soyfix[.]com/log/log/.

Infection mechanisms

The page displays a convincing replica of the legitimate WordPress payment interface, complete with accurate pricing breakdowns, VAT calculations, and branded payment method logos.

Phishing Landing Page (Source – Malwr-Analysis)

The phishing portal collects cardholder information through a JavaScript form that captures the cardholder name, card number, expiry date, and CVV.

Upon submission, this sensitive data is sent via POST request to a backend script named send_payment.php, which immediately forwards the stolen credentials to attacker-controlled Telegram bots.

The deception deepens through a second stage targeting two-factor authentication. After card submission, victims encounter a fake 3D Secure verification modal displaying merchant details, transaction references, and amounts.

Users are prompted to enter SMS OTPs. However, the verification process deliberately returns a “Verification failed” message regardless of whether the OTP is correct.

Fake 3-D Secure Verification & OTP Theft (Source – Malwr-Analysis)

This forces victims to retry multiple times, allowing attackers to harvest numerous valid OTP codes sent to the victim’s mobile device. These codes are immediately relayed to Telegram channels through a separate send_sms.php endpoint.

The campaign employs psychological trust mechanisms including artificial loading delays—a seven-second pause after payment submission and four-second verification processing delays—to convince victims they are engaging with legitimate banking infrastructure.

These deliberate delays reduce user suspicion and increase the likelihood of compliance.

The attackers cleverly avoid traditional command-and-control infrastructure by leveraging Telegram as their primary exfiltration channel. This approach offers several advantages: minimal infrastructure costs, built-in encryption, difficulty in disruption, and reduced detectability compared to conventional hosted panels.

Email header analysis reveals the campaign originates from theyounginevitables[.]com relayed through Alibaba Cloud SMTP infrastructure, with a weak DMARC policy offering no protection against spoofing.

Organizations should educate administrators to never click domain renewal links in emails and instead verify all renewal notices directly through official WordPress dashboards.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago