When Good Software Goes Bad

When Good Software Goes Bad

Most often bad actors try their best to hide their activities by using obfuscated code or by uploading fake plugins or themes that inject simple but malicious scripts into a site. Every now and then we encounter a case where legitimate software is used for malicious purposes.

We recently uncovered a case where Sypex Dumper, a valid database backup utility, was injected into the WordPress files. When checking the core WordPress integrity, we noticed a file at wp-content/fonts/font.php.

Continue reading When Good Software Goes Bad at Sucuri Blog.

Read more: When Good Software Goes Bad

Story added 18. April 2025, content source with full text you can find at link above.