Warning: Supply Chain Attack Targets Gravity Forms Plugin on WordPress

Just a SOC Analyst ^^
Search for a command to run...

Just a SOC Analyst ^^
No comments yet. Be the first to comment.
Tổng Quan Hãy tưởng tượng: một nhân viên nhân sự tại một công ty hàng không ở Pakistan nhận được lời mời phỏng vấn hấp dẫn từ một thương hiệu tuyển dụng có vẻ rất quen thuộc. Một cuộc gọi video được l

Tóm tắt Ngày 19/03/2026, cơ quan chức năng Mỹ, Canada và Đức triệt phá hạ tầng của bốn botnet IoT lớn nhất từng được ghi nhận — Aisuru, Kimwolf, JackSkid và Mossad. Hơn ba triệu thiết bị bị nhiễm. Hơn

Tóm tắt Không có malware nào trong chiến dịch này. Payload cuối cùng mà nạn nhân nhận được là trình cài đặt chính thức của Level RMM, tải trực tiếp từ hạ tầng của chính Level, cài đặt bằng msiexec với

Phần lớn dữ liệu thu được từ một honeypot SSH internet-facing là nhiễu: dò mật khẩu liên tục, hoặc bot đăng nhập thành công rồi tải payload xuống chạy ngay lập tức. Nhưng ngày 27/6/2026, honeypot của

Từ tháng 1/2025, một nhóm tấn công chưa xác định danh tính đã duy trì hoạt động gián điệp mạng nhắm vào các cơ quan chính phủ tại Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan và Syria,

Gravity Forms, a legitimate WordPress plugin, was recently discovered to contain a backdoor following a supply chain attack. Created by Rocketgenius, Gravity Forms allows the creation of professional forms on WordPress websites and is used on over 5 million websites, according to the company's official website.
Date of Discovery: July 11, 2025, security experts from Patchstack announced the discovery of malware and a backdoor in the Gravity Forms plugin for WordPress.
Scope of Impact: Only Gravity Forms versions 2.9.11.1 and 2.9.12 downloaded manually from gravityforms[.]com around July 9-10, 2025, are affected.
Method of Intrusion: The attacker illegally tampered with the manual download packages. The automatic update system and API of Gravity Forms were not compromised.
The malware communicates with the fake domain gravityapi[.]org (now disabled).
Once infected, the malware sends website information (URL, site name, WordPress Core version, PHP) to a malicious server, then downloads a payload in base64 format and saves it to wp-includes/bookmark-canonical.php.
This payload allows the attacker to execute unauthorized eval() commands (remote code execution - RCE), which can:
Create or delete user accounts.
Upload malicious files.
Execute arbitrary code.
Users can access one of the following URLs (replace {your_domain} with the actual domain name):
{your_domain}/wp-content/plugins/gravityforms/notification.php?gf_api_token=Cx3VGSwAHkB9yzIL9Qi48IFHwKm4sQ6Te5odNtBYu6Asb9JX06KYAWmrfPtG1eP3&action=ping
{your_domain}/wp-content/plugins/gravityforms_2.9.11.1/notification.php?gf_api_token=Cx3VGSwAHkB9yzIL9Qi48IFHwKm4sQ6Te5odNtBYu6Asb9JX06KYAWmrfPtG1eP3&action=ping
{your_domain}/wp-content/plugins/gravityforms_2.9.12/notification.php?gf_api_token=Cx3VGSwAHkB9yzIL9Qi48IFHwKm4sQ6Te5odNtBYu6Asb9JX06KYAWmrfPtG1eP3&action=ping
If the response is:
Warning: Undefined array key “gf_api_action” in...it means the website is infected with malware.
gravityapi[.]org |
| 185.243.113[.]108 |
| 185.193.89[.]19 |
| 24.245.59[.]0 |
| 194.87.63[.]219 |
FPT Threat Intelligence recommends several measures for organizations and individuals to prevent risks from supply chain attacks targeting WordPress plugins, such as the Gravity Forms incident:
From Gravity Forms:
Change all server authentication information.
Change passwords for all admin accounts.
Notify domain registrars and hosting providers to handle malicious domains and IPs.
Collaborate with organizations to report CVEs.
For users:
Restore the website to a safe state from a backup before July 9, 2025.
If no backup is available, perform the following:
Disable and delete the infected plugin (2.9.11.1 or 2.9.12).
Download and install a clean version (2.9.13 or later).
Block the following malicious domains and IPs at the firewall or security plugin.
Conduct a comprehensive check:
Review admin accounts, plugins, and system logs.
Remove unusual accounts and change admin passwords.