This is a post—the first of many—to encourage discussion about what we’re seeing out there in terms of threat actor activity. I’ll go first:
- Lots of ClickFix with
mshtaorpcalua.exe-flavored execution strings - WP2Shell recon
I’m confident these are related. There’s no doubt in my mind that WP2Shell exploitation will lead to higher numbers of WordPress sites delivering ClickFix payloads.
What about you? What are you seeing?