Threat reportMalwareTL-2026-0663
WordPress Malware Abuses Steam Community Profiles for C2 — Unicode Steganography, AES-256-CTR Payloads, Cookie-Auth PHP Backdoor + JS Injection (~1,980 Sites, GoDaddy)
WordPress Malware Abuses Steam Community Profiles for C2 (TL-2026-0663), also tracked as Steam C2 WordPress Malware, is a high-severity malware campaign, first published 2026-06-02. It has no confirmed attribution, affects WordPress WordPress (self-hosted), maps to 15 MITRE ATT&CK techniques (T1001.002, T1027, T1027.013), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0663
- Threat ID
- TL-2026-0663
- Also known as
- Steam C2 WordPress Malware, Steam Profile Comment C2 Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- web-hosting, small-business, e-commerce, media, general
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How WordPress Malware Abuses Steam Community Profiles for C2 works
A WordPress malware campaign disclosed by GoDaddy Security (first detected July 2025, ~1,980 infected sites) hides AES-256-CTR-encrypted C2 instructions inside Steam Community profile comments using six invisible Unicode characters. Infected sites scrape attacker-controlled Steam profiles, decode the hidden payload to build a hello-mywordl[.]info URL, and inject attacker JavaScript into every front-end page. A second-stage cookie-authenticated PHP backdoor enables base64-encoded PHP RCE for persistence.
GoDaddy Security disclosed an active WordPress compromise campaign that turns Valve's Steam Community platform into a resilient dead-drop command-and-control (C2) channel. Since first detection in July 2025, GoDaddy engineers have remediated the malware on approximately 1,980 WordPress installations. The campaign is notable for hiding C2 instructions in plain sight on a trusted, high-reputation third-party service, making outbound C2 traffic blend in with legitimate user activity and frustrating reputation- and domain-based blocking.
C2 RESOLUTION (Steam dead drop). On WordPress page load, the first-stage implant issues an outbound request to one of several attacker-controlled Steam Community profiles (e.g. /profiles/76561199096946028/ and the vanity IDs ravypadliha, enomisvool123, eremohin342) and scrapes the profile comment text. The comments appear benign — sometimes rendered as ASCII art — but carry a payload encoded with six invisible Unicode code points: U+200C (zero-width non-joiner), U+200D (zero-width joiner), U+2061 (function application), U+2062 (invisible times), U+2063 (invisible separator), and U+2064 (invisible plus). The decoder maps each character to a value 0-5, converts each to 2 bits, reassembles bytes, and applies a bitwise NOT. Decoded payloads are cached locally in WordPress transients under the _transient_caption_ prefix to reduce repeat scraping.
CRYPTOGRAPHY. The hidden payload is optionally protected with a well-engineered crypto stack: AES-256-CTR for confidentiality, PBKDF2-HMAC-SHA512 (10,000 iterations) for key derivation, and HMAC-SHA256 for integrity. The wire format is an 8-byte salt, followed by a 32-byte HMAC, followed by ciphertext; HMAC verification uses constant-time comparison (PHP hash_equals) to resist timing attacks. This is materially more disciplined than typical commodity WordPress malware and indicates a capable operator.
FRONT-END JAVASCRIPT INJECTION. The decoded instruction is used to construct a hello-mywordl[.]info URL that is enqueued into every front-end page via the WordPress wp_enqueue_scripts hook under the handle 'asahi-jquery-min-bundle'. The observed script (https://hello-mywordl[.]info/js/lodash.core.min.js) is disguised as a legitimate JavaScript library. This gives the operator arbitrary client-side code execution against every site visitor — usable for redirects, malvertising, skimming, or drive-by delivery.
SECOND-STAGE PHP BACKDOOR. For server-side persistence and control, the malware installs a cookie-authenticated PHP backdoor embedded in plugin/theme files (observed in /wp-content/themes/gt3-child/functions.php). A request carrying the DEpjndDbNc cookie returns a keepalive/version banner ('OK\nV:1767964512', a Unix epoch ~2026-01-09 indicating ongoing sample versioning). A request carrying the tEcaKKXEsb cookie accepts base64-encoded PHP supplied in the POST parameter new_code and executes it, yielding full remote code execution. The backdoor locates its own code by searching plugin/theme directories for the unique function-name marker G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72 and rewrites matching lines, enabling self-update and re-infection after partial cleanup.
INITIAL ACCESS (assessed, not confirmed). GoDaddy did not identify a single exploited CVE. The assessed entry vectors are stolen WordPress admin credentials, compromised FTP/SFTP access, exploitation of a vulnerable theme/plugin, or supply-chain compromise of a theme/plugin. No threat actor, nation-state, or named malware family has been attributed.
DEFENDER IMPACT. Because cleanup that leaves any backdoor component active allows the attacker to reinstall removed code, remediation must be complete: restore from a known-clean backup predating infection where possible, or fully remove all malicious code, purge the _transient_caption_ transients, rotate all credentials, and update core/plugins/themes. SOC value lies in detecting outbound WordPress-server connections to steamcommunity.com, references to hello-mywordl[.]info, the unique marker string, and the two authentication cookies.
MITRE ATT&CK techniques used in TL-2026-0663
Command and Control
T1001.002 Data Obfuscation: Steganography; T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography; T1659 Content Injection
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter: JavaScript
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Persistence
Affected products and versions in WordPress Malware Abuses Steam Community Profiles for C2
- WordPress — WordPress (self-hosted)
Vulnerable versions: any version with compromised admin/FTP creds or a vulnerable theme/plugin - GT3 Themes — gt3-child theme (observed infection host file)
Vulnerable versions: functions.php as observed dropper location
Remediation for WordPress Malware Abuses Steam Community Profiles for C2
Patches
- No vendor patch — this is a post-compromise malware campaign, not a single CVE. Keep WordPress core, themes, and plugins fully updated to close the assessed entry vectors.
Immediate actions
- Block and alert on outbound connections from WordPress/web servers to steamcommunity.com (servers have no business reason to scrape Steam profiles).
- Block the domain hello-mywordl[.]info at DNS/egress and remove any enqueued script referencing it.
- Search all plugin/theme files for the marker string G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72 and remove the backdoor.
- Search for and delete the authentication-cookie logic referencing DEpjndDbNc and tEcaKKXEsb, and the new_code POST handler.
- Purge WordPress transients with the _transient_caption_ prefix (wp_options / object cache).
Workarounds
- Disable theme/plugin file editing in WordPress (define('DISALLOW_FILE_EDIT', true);).
- Apply egress filtering / allowlisting so the server cannot make arbitrary outbound HTTPS requests.
Longer-term hardening
- Restore from a known-clean backup predating July 2025 / the infection date where available — partial cleanup is unreliable because the backdoor can reinstall removed code.
- Rotate all WordPress admin, database, FTP/SFTP, and hosting credentials; enforce MFA on admin and hosting panels.
- Deploy file-integrity monitoring on wp-content/themes and wp-content/plugins to catch functions.php tampering.
- Enforce least-privilege file permissions so the web user cannot rewrite theme/plugin PHP at runtime.
Weaknesses (CWE) in WordPress Malware Abuses Steam Community Profiles for C2
Timeline of WordPress Malware Abuses Steam Community Profiles for C2
- Domain hello-mywordl[.]info and JS payload /js/lodash.core.min.js (enqueue handle asahi-jquery-min-bundle) confirmed as the front-end injection infrastructure.
- BleepingComputer, Security Affairs, Hackread, and SC Media publish secondary coverage; IOCs (hello-mywordl[.]info, four Steam profiles, marker string, auth cookies) circulated.
- GoDaddy publishes technical analysis detailing the Unicode steganography, AES-256-CTR/PBKDF2-SHA512/HMAC-SHA256 crypto stack, the JS injection, and the cookie-authenticated PHP backdoor.
- GoDaddy Security detects the campaign; malware identified across approximately 1,980 WordPress installations using Steam Community profiles as a C2 dead drop.
- Captured backdoor ping returns 'OK\nV:1767964512' — a Unix epoch ~2026-01-09 — indicating continued sample versioning and an ongoing, maintained operation months after disclosure.
- Threadlinqs Intelligence publishes full threat record with MITRE mapping, IOCs, detections, and attack simulation for SOC consumption.
Sources cited for WordPress Malware Abuses Steam Community Profiles for C2
- Malware Targeting WordPress Abuses Steam Community Profiles for Command & Control Operations
- WordPress malware campaign hides payloads in Steam profiles
- GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
- New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions
- Malware hides in Steam comments to infect WordPress sites
- Steam C2 WordPress Malware: Backdoor Cleanup Checklist
Detection coverage for TL-2026-0663
As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0663 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.