WordPress XML-RPC Flaw Led to Full VPS Takeover and Crypto Mining
A developer discovered their client's VPS had been fully compromised after attackers exploited a vulnerable WordPress installation, likely via XML-RPC or an arbitrary file upload flaw. The breach went beyond the website itself — attackers created rogue admin accounts in WordPress and CyberPanel, added unauthorized SSH keys, and planted a root-level OS user. Malicious PHP files were hidden inside deeply nested directories, and a disguised crypto-mining process called libnet-cache was configured to automatically restart if killed. Persistence was enforced through tampered systemd services, malicious cron jobs, and immutable file attributes that initially blocked even root-level deletion. Cleanup required restoring the chattr binary, stripping immutable flags, removing all unauthorized access points, and reinstalling WordPress core via WP-CLI.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in