Threat reportMalwareTL-2026-0663

WordPress Malware Abuses Steam Community Profiles for C2 — Unicode Steganography, AES-256-CTR Payloads, Cookie-Auth PHP Backdoor + JS Injection (~1,980 Sites, GoDaddy)

highACTIVE

WordPress Malware Abuses Steam Community Profiles for C2 (TL-2026-0663), also tracked as Steam C2 WordPress Malware, is a high-severity malware campaign, first published 2026-06-02. It has no confirmed attribution, affects WordPress WordPress (self-hosted), maps to 15 MITRE ATT&CK techniques (T1001.002, T1027, T1027.013), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0663

Threat ID
TL-2026-0663
Also known as
Steam C2 WordPress Malware, Steam Profile Comment C2 Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
web-hosting, small-business, e-commerce, media, general
Target regions
Global
Detection rules
9
Indicators of compromise
16

How WordPress Malware Abuses Steam Community Profiles for C2 works

A WordPress malware campaign disclosed by GoDaddy Security (first detected July 2025, ~1,980 infected sites) hides AES-256-CTR-encrypted C2 instructions inside Steam Community profile comments using six invisible Unicode characters. Infected sites scrape attacker-controlled Steam profiles, decode the hidden payload to build a hello-mywordl[.]info URL, and inject attacker JavaScript into every front-end page. A second-stage cookie-authenticated PHP backdoor enables base64-encoded PHP RCE for persistence.

GoDaddy Security disclosed an active WordPress compromise campaign that turns Valve's Steam Community platform into a resilient dead-drop command-and-control (C2) channel. Since first detection in July 2025, GoDaddy engineers have remediated the malware on approximately 1,980 WordPress installations. The campaign is notable for hiding C2 instructions in plain sight on a trusted, high-reputation third-party service, making outbound C2 traffic blend in with legitimate user activity and frustrating reputation- and domain-based blocking.

C2 RESOLUTION (Steam dead drop). On WordPress page load, the first-stage implant issues an outbound request to one of several attacker-controlled Steam Community profiles (e.g. /profiles/76561199096946028/ and the vanity IDs ravypadliha, enomisvool123, eremohin342) and scrapes the profile comment text. The comments appear benign — sometimes rendered as ASCII art — but carry a payload encoded with six invisible Unicode code points: U+200C (zero-width non-joiner), U+200D (zero-width joiner), U+2061 (function application), U+2062 (invisible times), U+2063 (invisible separator), and U+2064 (invisible plus). The decoder maps each character to a value 0-5, converts each to 2 bits, reassembles bytes, and applies a bitwise NOT. Decoded payloads are cached locally in WordPress transients under the _transient_caption_ prefix to reduce repeat scraping.

CRYPTOGRAPHY. The hidden payload is optionally protected with a well-engineered crypto stack: AES-256-CTR for confidentiality, PBKDF2-HMAC-SHA512 (10,000 iterations) for key derivation, and HMAC-SHA256 for integrity. The wire format is an 8-byte salt, followed by a 32-byte HMAC, followed by ciphertext; HMAC verification uses constant-time comparison (PHP hash_equals) to resist timing attacks. This is materially more disciplined than typical commodity WordPress malware and indicates a capable operator.

FRONT-END JAVASCRIPT INJECTION. The decoded instruction is used to construct a hello-mywordl[.]info URL that is enqueued into every front-end page via the WordPress wp_enqueue_scripts hook under the handle 'asahi-jquery-min-bundle'. The observed script (https://hello-mywordl[.]info/js/lodash.core.min.js) is disguised as a legitimate JavaScript library. This gives the operator arbitrary client-side code execution against every site visitor — usable for redirects, malvertising, skimming, or drive-by delivery.

SECOND-STAGE PHP BACKDOOR. For server-side persistence and control, the malware installs a cookie-authenticated PHP backdoor embedded in plugin/theme files (observed in /wp-content/themes/gt3-child/functions.php). A request carrying the DEpjndDbNc cookie returns a keepalive/version banner ('OK\nV:1767964512', a Unix epoch ~2026-01-09 indicating ongoing sample versioning). A request carrying the tEcaKKXEsb cookie accepts base64-encoded PHP supplied in the POST parameter new_code and executes it, yielding full remote code execution. The backdoor locates its own code by searching plugin/theme directories for the unique function-name marker G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72 and rewrites matching lines, enabling self-update and re-infection after partial cleanup.

INITIAL ACCESS (assessed, not confirmed). GoDaddy did not identify a single exploited CVE. The assessed entry vectors are stolen WordPress admin credentials, compromised FTP/SFTP access, exploitation of a vulnerable theme/plugin, or supply-chain compromise of a theme/plugin. No threat actor, nation-state, or named malware family has been attributed.

DEFENDER IMPACT. Because cleanup that leaves any backdoor component active allows the attacker to reinstall removed code, remediation must be complete: restore from a known-clean backup predating infection where possible, or fully remove all malicious code, purge the _transient_caption_ transients, rotate all credentials, and update core/plugins/themes. SOC value lies in detecting outbound WordPress-server connections to steamcommunity.com, references to hello-mywordl[.]info, the unique marker string, and the two authentication cookies.

MITRE ATT&CK techniques used in TL-2026-0663

Command and Control

T1001.002 Data Obfuscation: Steganography; T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography; T1659 Content Injection

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter: JavaScript

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain

Persistence

T1505.003 Server Software Component: Web Shell

Affected products and versions in WordPress Malware Abuses Steam Community Profiles for C2

  • WordPress — WordPress (self-hosted)
    Vulnerable versions: any version with compromised admin/FTP creds or a vulnerable theme/plugin
  • GT3 Themes — gt3-child theme (observed infection host file)
    Vulnerable versions: functions.php as observed dropper location

Remediation for WordPress Malware Abuses Steam Community Profiles for C2

Patches

  • No vendor patch — this is a post-compromise malware campaign, not a single CVE. Keep WordPress core, themes, and plugins fully updated to close the assessed entry vectors.

Immediate actions

  • Block and alert on outbound connections from WordPress/web servers to steamcommunity.com (servers have no business reason to scrape Steam profiles).
  • Block the domain hello-mywordl[.]info at DNS/egress and remove any enqueued script referencing it.
  • Search all plugin/theme files for the marker string G7jp2L84mnVc4LNW9wcbZcaVFAyC9N72 and remove the backdoor.
  • Search for and delete the authentication-cookie logic referencing DEpjndDbNc and tEcaKKXEsb, and the new_code POST handler.
  • Purge WordPress transients with the _transient_caption_ prefix (wp_options / object cache).

Workarounds

  • Disable theme/plugin file editing in WordPress (define('DISALLOW_FILE_EDIT', true);).
  • Apply egress filtering / allowlisting so the server cannot make arbitrary outbound HTTPS requests.

Longer-term hardening

  • Restore from a known-clean backup predating July 2025 / the infection date where available — partial cleanup is unreliable because the backdoor can reinstall removed code.
  • Rotate all WordPress admin, database, FTP/SFTP, and hosting credentials; enforce MFA on admin and hosting panels.
  • Deploy file-integrity monitoring on wp-content/themes and wp-content/plugins to catch functions.php tampering.
  • Enforce least-privilege file permissions so the web user cannot rewrite theme/plugin PHP at runtime.

Weaknesses (CWE) in WordPress Malware Abuses Steam Community Profiles for C2

CWE-506, CWE-912, CWE-94, CWE-79, CWE-285, CWE-829

Timeline of WordPress Malware Abuses Steam Community Profiles for C2

  • Domain hello-mywordl[.]info and JS payload /js/lodash.core.min.js (enqueue handle asahi-jquery-min-bundle) confirmed as the front-end injection infrastructure.
  • BleepingComputer, Security Affairs, Hackread, and SC Media publish secondary coverage; IOCs (hello-mywordl[.]info, four Steam profiles, marker string, auth cookies) circulated.
  • GoDaddy publishes technical analysis detailing the Unicode steganography, AES-256-CTR/PBKDF2-SHA512/HMAC-SHA256 crypto stack, the JS injection, and the cookie-authenticated PHP backdoor.
  • GoDaddy Security detects the campaign; malware identified across approximately 1,980 WordPress installations using Steam Community profiles as a C2 dead drop.
  • Captured backdoor ping returns 'OK\nV:1767964512' — a Unix epoch ~2026-01-09 — indicating continued sample versioning and an ongoing, maintained operation months after disclosure.
  • Threadlinqs Intelligence publishes full threat record with MITRE mapping, IOCs, detections, and attack simulation for SOC consumption.

Sources cited for WordPress Malware Abuses Steam Community Profiles for C2

Detection coverage for TL-2026-0663

As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0663 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats