Skip to content
Tech News
← Back to articles

Hackers abuse Google ads for GoDaddy ManageWP login phishing

read original get Phishing Awareness Poster → more articles
Why This Matters

This phishing campaign highlights the evolving sophistication of cyber threats targeting popular website management platforms like ManageWP. By leveraging Google ads and real-time adversary-in-the-middle techniques, attackers can effectively steal credentials and compromise a vast number of WordPress sites, posing significant risks to web developers, agencies, and enterprises. The incident underscores the importance of heightened vigilance and improved security measures in the digital ecosystem.

Key Takeaways

A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites.

The threat actor is using an adversary-in-the-middle (AitM) approach where the fake login page acts as a real-time proxy between the victim and the legitimate ManageWP service.

ManageWP is a centralized remote administration platform for WordPress websites, enabling users to manage multiple sites from a single panel instead of logging into separate dashboards. Common users include web developers, web agencies managing client sites, and enterprises.

Researchers at Guardio Labs warn that the fake result is displayed above the real one for the 'managewp' query, luring users who rely on Google to find the URL for logging into ManageWP.

Malicious Google Search result

Source: Guardio Labs

Users clicking on the malicious result are taken to a login page that looks identical to the real one. However, any credentials typed in are delivered to a Telegram channel controlled by the attacker.

Unlike the more common phishing pages that capture username and password pairs, the campaign uses a live AiTM setup, as the attacker uses the credentials to log into the platform in real-time.

The victim is then served a fake prompt to enter the two-factor authentication (2FA) code, which the threat actor uses to gain access to the ManageWP account.

Guardio Labs head researcher Nati Tal told BleepingComputer that each ManageWP account typically hosts hundreds of sites.

... continue reading