WpBruteBot
- First seen
- 2020-07-15 00:00:00
- Malware type
- botnet, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:26:35
Targeted industries: technology-and-telecommunications retail-and-hospitality
Context
WpBruteBot is a botnet malware that targets WordPress sites using brute-force attacks to compromise login credentials. It facilitates unauthorized access and often installs additional malicious payloads.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Wpbrutebot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Wpbrutebot (report)
- zscaler.com — Malware Leveraging Xml Rpc Vulnerability Exploit Wordpress Sites (report)