Security · WordPress
Eight infected WordPress sites, one hosting plan, thirteen days of malware
Eight WordPress sites sharing a single hosting plan had been serving malware for thirteen days before anyone noticed. There were two separate payloads, and one of them included an admin account that rebuilt itself every time it was deleted.
Read the Full Case StudyThe Problem
- Malware running across eight sites on the same hosting account
- Two different payloads, so cleaning one left the other active
- A persistence mechanism that recreated a rogue administrator account after deletion
- Shared hosting meant any site left untouched could reinfect the rest
What I Did
- Scoped the infection. Checked every site on the account, not only the one that was reported.
- Removed both payloads. Cleaned core files, themes, plugins, uploads and the database on each site.
- Killed the persistence. Found and removed the code that kept rebuilding the admin account.
- Traced the source. Identified how the reinfection was happening so it could be closed off.
- Hardened the environment. Updates, cleanup of unused plugins and themes, permissions and login protection across the account.
The Result
All eight sites were cleaned and the hosting environment hardened. A basic “scan and delete” cleanup would have left the self-rebuilding admin in place and the sites would have been reinfected.
Site Hacked?
I clean WordPress infections completely, repair the SEO damage and harden the site so it stays clean.
WordPress Malware Removal