Threat reportMalwareTL-2026-2205

Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual Webshells via Database Injection

criticalACTIVE

Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual (TL-2026-2205), also tracked as Beloved PBN Entegrasyonu, is a critical-severity malware campaign, first published 2026-06-16. It has no confirmed attribution, affects N/A (malicious third-party plugin, not an official WordPress.org, maps to 9 MITRE ATT&CK techniques (T1005, T1036, T1059), and is covered by 9 detection rules and 5 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
5Indicators of compromise

Key facts for TL-2026-2205

Threat ID
TL-2026-2205
Also known as
Beloved PBN Entegrasyonu
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
websites, digital media
Target regions
Global
Detection rules
9
Indicators of compromise
5

Malware and tooling in Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

Malware and tooling: Beloved PBN Entegrasyonu

How Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual works

A fake WordPress plugin, 'Beloved PBN Entegrasyonu', beacons the compromised site's URL to an external C2 API on every page load and injects attacker-supplied HTML/JavaScript into the page footer, while separately planting two PHP webshells directly inside wp_posts database records rather than on the filesystem. The database-resident webshells grant unauthenticated, unrestricted read/write access to the entire server filesystem and are purpose-built to evade file-based malware scanners.

Sucuri incident responders identified a fake WordPress plugin named 'Beloved PBN Entegrasyonu' (Turkish: "Beloved PBN Integration") planted on a compromised WordPress site at wp-content/plugins/beloved-pbn/beloved-pbn.php. Rather than providing any legitimate PBN (Private Blog Network) functionality, the plugin's actual purpose was to silently beacon the compromised site's URL to an external API — hxxps://wp-tracker[.]com/api.php — on every page load, and to echo whatever HTML or JavaScript the C2 server returned directly into the page footer. To avoid printing garbage or tipping off defenders when the C2 was offline or returned unexpected data, the injection logic only executes/prints C2 responses containing a specific marker string. The plugin's metadata (Plugin URI) points to a second attacker-controlled domain, hxxps://destangelirvip[.]com.

Separately from the plugin, the attackers staged two PHP webshells as raw executable code stored directly inside wp_posts database records rather than as files on disk — a deliberate choice to evade file-based malware scanners that only inspect the filesystem. Both webshells are reachable over HTTP with no authentication or IP restriction and expose an action-handler model driven by attacker-submitted parameters, providing unrestricted file read, write, delete, rename, and permission-modification across the entire server filesystem, unrestricted file upload with no extension filtering, and unrestricted directory traversal. One of the two webshells additionally hides itself from directory listings so it will not appear if an administrator browses the plugin directory. Outbound requests from the malware spoof a Chrome 120 User-Agent string, and source-code comments explicitly reference bypassing FortiGuard web filtering.

Sucuri assesses the campaign as run by a Turkish-speaking threat actor operating a classic black-hat SEO monetization scheme: the database-resident access and footer injection are used to plant hidden backlinks as part of a Private Blog Network, most likely tied to gambling and adult-affiliate niches. The injected outbound links risk damaging the compromised site's own search rankings and can trigger manual actions in Google Search Console. No CVE applies — this is a malicious, self-installed fake plugin rather than a vulnerability in a legitimate one; the underlying access vector used to plant the plugin on the victim site in the first place is not documented in available sourcing. Sucuri published a SQL hunting query against wp_posts and remediation guidance (plugin/database cleanup, credential rotation, wp_users audit) alongside the disclosure.

MITRE ATT&CK techniques used in TL-2026-2205

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading; T1564 Hide Artifacts; T1564.001 Hidden Files and Directories

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071.001 Web Protocols

Persistence

T1505.003 Web Shell

Resource Development

T1583.001 Domains; T1584.004 Server

Affected products and versions in Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

  • N/A (malicious third-party plugin, not an official WordPress.org listing or a vulnerability in legitimate software) — Self-hosted WordPress sites on which the fake 'Beloved PBN Entegrasyonu' plugin was installed
    Vulnerable versions: Any WordPress installation where the fake plugin was manually installed/activated after the attacker obtained prior access
    Fixed in: N/A — remediation is removal of the malicious plugin and database-resident webshells, not a software patch

Remediation for Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

Immediate actions

  • Remove the wp-content/plugins/beloved-pbn/ directory and deactivate/delete the 'Beloved PBN Entegrasyonu' plugin
  • Query wp_posts for records matching post_content LIKE '%<?php%' OR post_content LIKE '%file_put_contents%' OR post_content LIKE '%file_get_contents%' OR post_content LIKE '%eval(%' and remove the malicious rows
  • Block outbound and inbound traffic to wp-tracker[.]com and destangelirvip[.]com at the perimeter/WAF

Longer-term hardening

  • Audit wp_users for unauthorized administrator accounts created via the webshells
  • Rotate all WordPress admin, database, and hosting credentials
  • Deploy database-content integrity monitoring (not just filesystem file-integrity monitoring) that inspects wp_posts for embedded PHP/eval payloads

Weaknesses (CWE) in Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

CWE-94, CWE-306, CWE-829, CWE-912

Timeline of Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

  • Sucuri publishes a public technical write-up including a wp_posts hunting SQL query and remediation guidance (plugin removal, database cleanup, credential rotation, wp_users audit).
  • Sucuri assesses the campaign as run by a Turkish-speaking threat actor operating a gambling/adult-affiliate Private Blog Network hidden-backlink monetization scheme.
  • Self-hiding directory-listing evasion in one webshell, Chrome 120 User-Agent spoofing, and explicit FortiGuard-bypass comments are identified in the malware.
  • Two PHP webshells are found stored as raw executable code inside wp_posts database records rather than on the filesystem, exposing unauthenticated full-filesystem read/write/upload/traversal via an attacker-driven action handler.
  • Beacon and footer-injection logic is identified in the plugin, calling hxxps://wp-tracker[.]com/api.php on every page load and injecting the marker-gated response into the page footer.
  • Sucuri incident responders identify a fake plugin, 'Beloved PBN Entegrasyonu', at wp-content/plugins/beloved-pbn/beloved-pbn.php on a compromised WordPress site during cleanup.

Sources cited for Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual

Detection coverage for TL-2026-2205

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2205 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
5 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats