DollyWay

Malware type
downloader, botnet
Family
Malware family
Profile updated
2026-07-07 14:38:09

Targeted industries: retail-and-hospitality technology-and-telecommunications media-and-entertainment

Context

PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes. Delivers signed payloads, maintains persistence via helper files, and redirects traffic to monetized scam networks.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Php.Dollyway (report)
  • blogs.infoblox.com — Vexing And Vicious The Eerie Relationship Between Wordpress Hackers And An Adtech Cabal (report)
  • godaddy.com — Dollyway World Domination (report)
  • godaddy.com — Dollyway Malware C2 Tds (report)

External references