Sucuri: Malware Disables Security Plugins to Avoid Detection

An alarm or monitoring system is a great tool that can be used to improve the security of a home or website, but what if an attacker can easily disable it?

Sucuri recently described an exploit in which hackers gain access to the site and then immediately disable any of a list of well known security plugins which are installed. If you security plugins are turned off, they’re not going to scan your site for malware and they’re not going to email you a warning.

“If a user tries to reactivate one of the disabled security plugins, it will momentarily appear to activate only for the malware to immediately disable it again. This behavior will prevail until the malware is fully removed from the compromised environment, making it more difficult to detect malicious behavior on the website.”

Ideally your sites are locked down well enough that the hackers can’t gain access in the first place. But keep an eye on your site and if you see any behavior similar to what’s described, contact us and we’ll clean it up.

https://blog.sucuri.net/2020/09/wordpress-malware-disables-security-to-avoid-detection.html

Posted in Exploit, Hack.