# Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual Webshells via Database Injection

> A fake WordPress plugin, 'Beloved PBN Entegrasyonu', beacons the compromised site's URL to an external C2 API on every page load and injects attacker-supplied HTML/JavaScript into the page footer, while separately planting two PHP webshells directly inside wp_posts database records rather than on the filesystem. The database-resident webshells grant unauthenticated, unrestricted read/write access to the entire server filesystem and are purpose-built to evade file-based malware scanners.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2205
- **ID:** TL-2026-2205
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 5 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Sucuri incident responders identified a fake WordPress plugin named 'Beloved PBN Entegrasyonu' (Turkish: "Beloved PBN Integration") planted on a compromised WordPress site at wp-content/plugins/beloved-pbn/beloved-pbn.php. Rather than providing any legitimate PBN (Private Blog Network) functionality, the plugin's actual purpose was to silently beacon the compromised site's URL to an external API — hxxps://wp-tracker[.]com/api.php — on every page load, and to echo whatever HTML or JavaScript the C2 server returned directly into the page footer. To avoid printing garbage or tipping off defenders when the C2 was offline or returned unexpected data, the injection logic only executes/prints C2 responses containing a specific marker string. The plugin's metadata (Plugin URI) points to a second attacker-controlled domain, hxxps://destangelirvip[.]com.

Separately from the plugin, the attackers staged two PHP webshells as raw executable code stored directly inside wp_posts database records rather than as files on disk — a deliberate choice to evade file-based malware scanners that only inspect the filesystem. Both webshells are reachable over HTTP with no authentication or IP restriction and expose an action-handler model driven by attacker-submitted parameters, providing unrestricted file read, write, delete, rename, and permission-modification across the entire server filesystem, unrestricted file upload with no extension filtering, and unrestricted directory traversal. One of the two webshells additionally hides itself from directory listings so it will not appear if an administrator browses the plugin directory. Outbound requests from the malware spoof a Chrome 120 User-Agent string, and source-code comments explicitly reference bypassing FortiGuard web filtering.

Sucuri assesses the campaign as run by a Turkish-speaking threat actor operating a classic black-hat SEO monetization scheme: the database-resident access and footer injection are used to plant hidden backlinks as part of a Private Blog Network, most likely tied to gambling and adult-affiliate niches. The injected outbound links risk damaging the compromised site's own search rankings and can trigger manual actions in Google Search Console. No CVE applies — this is a malicious, self-installed fake plugin rather than a vulnerability in a legitimate one; the underlying access vector used to plant the plugin on the victim site in the first place is not documented in available sourcing. Sucuri published a SQL hunting query against wp_posts and remediation guidance (plugin/database cleanup, credential rotation, wp_users audit) alongside the disclosure.

## MITRE ATT&CK

- T1583.001 Domains
- T1584.004 Server
- T1505.003 Web Shell
- T1059 Command and Scripting Interpreter
- T1036 Masquerading
- T1564.001 Hidden Files and Directories
- T1564 Hide Artifacts
- T1005 Data from Local System
- T1071.001 Web Protocols

## Sources

- [WordPress PBN Plugin Drops Dual Webshells via Database Injection](https://blog.sucuri.net/2026/06/wordpress-pbn-plugin-drops-dual-webshells-via-database-injection.html)
- [Web Shells: Types, Mitigation & Removal](https://blog.sucuri.net/2026/03/web-shells.html)
- [Webshell in Fake Plugin /blnmrpb/ Directory](https://blog.sucuri.net/2020/01/webshell-in-fake-plugin-blnmrpb-directory.html)
- [Hidden SEO Spam Link Injections on WordPress Sites](https://blog.sucuri.net/2020/11/hidden-seo-spam-link-injections-on-wordpress-sites.html)
- [Massive Abuse of Abandoned Eval PHP WordPress Plugin](https://blog.sucuri.net/2023/04/massive-abuse-of-abandoned-evalphp-wordpress-plugin.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2205
