WpBruteBot

First seen
2020-07-15 00:00:00
Malware type
botnet, credential-stealer
Family
Malware family
Profile updated
2026-07-07 15:26:35

Targeted industries: technology-and-telecommunications retail-and-hospitality

Context

WpBruteBot is a botnet malware that targets WordPress sites using brute-force attacks to compromise login credentials. It facilitates unauthorized access and often installs additional malicious payloads.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Wpbrutebot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Wpbrutebot (report)
  • zscaler.com — Malware Leveraging Xml Rpc Vulnerability Exploit Wordpress Sites (report)

External references