{"id":9116,"date":"2022-03-21T12:44:03","date_gmt":"2022-03-21T12:44:03","guid":{"rendered":"https:\/\/www.hostingseekers.com\/blog\/?p=9116"},"modified":"2022-03-21T12:44:03","modified_gmt":"2022-03-21T12:44:03","slug":"godaddy-hosted-websites-got-infected-by-backdoor","status":"publish","type":"post","link":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/","title":{"rendered":"Hundreds of GoDaddy Hosted Websites are infected by Backdoor Malware in a Single Day"},"content":{"rendered":"<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Backdoor_(computing)\" rel=\"nofollow\"><span style=\"font-weight: 400;\">Backdoor<\/span><\/a><span style=\"font-weight: 400;\"> is a type of malware that nullifies the normal authentication procedure to access a system. Therefore, remote access is given to resources within an application like databases and file servers, which gives perpetrators the ability to access a system remotely using commands and they can easily update the malware.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Internet security analysts have identified a spike in backdoor infections on WordPress websites hosted on GoDaddy\u2019s <a href=\"https:\/\/www.hostingseekers.com\/category\/web-hosting\/wordpress-hosting\">Managed WordPress service<\/a>. All these websites featured an identical backdoor payload. This case has also affected other internet service resellers like<\/span> <span style=\"font-weight: 400;\">Host Europe Managed WordPress<\/span><span style=\"font-weight: 400;\">,<\/span> <span style=\"font-weight: 400;\">MediaTemple<\/span><span style=\"font-weight: 400;\">,<\/span> <span style=\"font-weight: 400;\">tsoHost<\/span><span style=\"font-weight: 400;\">,<\/span> <span style=\"font-weight: 400;\">123Reg<\/span><span style=\"font-weight: 400;\">,<\/span> <span style=\"font-weight: 400;\">Domain Factory<\/span><span style=\"font-weight: 400;\">, and<\/span> <span style=\"font-weight: 400;\">Heart Internet<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The investigation is first carried out by Wordfence whose team observed the malicious activity on March 11, 2022, where 298 websites got infected by the backdoor within 24 hours. 281 of these websites were hosted on GoDaddy.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-9117 size-large\" src=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-1024x427.webp\" alt=\"GoDaddy Hosted Websites got infected\" width=\"750\" height=\"313\" srcset=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-1024x427.webp 1024w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-300x125.webp 300w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-768x320.webp 768w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-1536x640.webp 1536w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-1568x654.webp 1568w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5-150x63.webp 150w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/diagram5.webp 1600w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<hr \/>\n<h2><b>Old Form Of Spamming \u2013<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The backdoor infecting all sites is a form of the 2015 Google search SEO-poisoning tool form. Where the tool is implanted on the wp-config.php to fetch spam link templates from the C2 that are used to inject malicious webpages into search results.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This spam campaign predominately used pharmaceutical spam templates and served the visitors of the compromised websites instead of the actual content.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The goal of this spam campaign was to entice victims to purchase fake products, lose victims\u2019 money and gather victims\u2019 payment details.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Also, the threat actors used to harm a website\u2019s reputation by altering its content and making the breach evident, although this wasn\u2019t their primary aim, at this time.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This type of attack is usually harder to detect and stop from the user\u2019s side. This is because, these attacks take place on the server and not on the browser, and as such, local internet security tools won\u2019t detect anything suspicious, making it unnoticeable.<\/span><\/p>\n<hr \/>\n<h2><b>Is it like Supply Chain Attack?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Although the intrusion vector of threat actors hasn\u2019t been determined, yet, this looks suspiciously close to a supply chain attack, but not yet confirmed.<\/span><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/\" rel=\"nofollow\"><span style=\"font-weight: 400;\">Bleeping Computer<\/span><\/a> <span style=\"font-weight: 400;\">has contacted GoDaddy and asked to find out more possibilities about the attack, but still, no answer has been delivered yet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">GoDaddy has disclosed a data breach in November 2021 that has affected nearly 1.2 million customers and multiple Managed WordPress service resellers, including the six that we have mentioned above.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That breach contains authorization access to the system that provisions the company\u2019s Managed WordPress sites. Still, it\u2019s not suggested to conclude that the two occurrences might be linked.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In any case, we advise that if your website is hosted on <a href=\"https:\/\/www.godaddy.com\/\" rel=\"nofollow\">GoDaddy<\/a>\u2019s Managed WordPress platform, then make sure to scan your wp-config.php file to identify the potential backdoor injections.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-9118 size-large\" src=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1-1024x617.webp\" alt=\"GoDaddy Hosted Websites got infected\" width=\"750\" height=\"452\" srcset=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1-1024x617.webp 1024w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1-300x181.webp 300w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1-768x463.webp 768w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1-150x90.webp 150w, https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/backdoor1.webp 1158w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Wordfence also wants to remind all admins that removing the backdoor should be your first step and removing spam search engine results should also be a priority.<\/span><\/p>\n<h4 id=\"047b\" class=\"ht hu dt hv b hw hx hy hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq dl eq\"><em>If you enjoyed reading this news, you are surely going to cherish these too \u2013<\/em><\/h4>\n<ul>\n<li><a href=\"https:\/\/www.hostingseekers.com\/blog\/runai-raised-75-million-dollar\/\">Run:ai Raised $75M in the latest Series C Funding Round<\/a><\/li>\n<li><a href=\"https:\/\/www.hostingseekers.com\/blog\/openmetal-created-new-private-cloud\/\">InMotion Hosting\u2019s OpenMetal Created A New Private Cloud Segment<\/a><\/li>\n<li><a href=\"https:\/\/www.hostingseekers.com\/blog\/cybersecurity-buys-identity-firm-attivo-networks-for-616-5m\/\">Cybersecurity Firm SentinelOne Buys Identity Firm Attivo Networks<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Backdoor is a type of malware that nullifies the normal authentication procedure to access a system. Therefore, remote access is&hellip; <a class=\"more-link\" href=\"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/\">Continue reading <span class=\"screen-reader-text\">Hundreds of GoDaddy Hosted Websites are infected by Backdoor Malware in a Single Day<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":9154,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[18,238],"tags":[],"class_list":["post-9116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-news","category-news","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hundreds of GoDaddy Hosted Websites got infected by Backdoor<\/title>\n<meta name=\"description\" content=\"Hundreds of websites hosted on GoDaddy\u2019s Managed WordPress hosting services got infected by Backdoor malware\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hundreds of GoDaddy Hosted Websites got infected by Backdoor\" \/>\n<meta property=\"og:description\" content=\"Hundreds of websites hosted on GoDaddy\u2019s Managed WordPress hosting services got infected by Backdoor malware\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/\" \/>\n<meta property=\"og:site_name\" content=\"Hostingseekers\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/hostingseekers\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-21T12:44:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"manvinder Singh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Hostingseekers1\" \/>\n<meta name=\"twitter:site\" content=\"@Hostingseekers1\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"manvinder Singh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hundreds of GoDaddy Hosted Websites got infected by Backdoor","description":"Hundreds of websites hosted on GoDaddy\u2019s Managed WordPress hosting services got infected by Backdoor malware","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/","og_locale":"en_US","og_type":"article","og_title":"Hundreds of GoDaddy Hosted Websites got infected by Backdoor","og_description":"Hundreds of websites hosted on GoDaddy\u2019s Managed WordPress hosting services got infected by Backdoor malware","og_url":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/","og_site_name":"Hostingseekers","article_publisher":"https:\/\/www.facebook.com\/hostingseekers","article_published_time":"2022-03-21T12:44:03+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg","type":"image\/jpeg"}],"author":"manvinder Singh","twitter_card":"summary_large_image","twitter_creator":"@Hostingseekers1","twitter_site":"@Hostingseekers1","twitter_misc":{"Written by":"manvinder Singh","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#article","isPartOf":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/"},"author":{"name":"manvinder Singh","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/person\/76bc9258cab3c5bfe0237d3e290b13ea"},"headline":"Hundreds of GoDaddy Hosted Websites are infected by Backdoor Malware in a Single Day","datePublished":"2022-03-21T12:44:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/"},"wordCount":525,"commentCount":0,"publisher":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg","articleSection":["Business News","News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#respond"]}],"copyrightYear":"2022","copyrightHolder":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/","url":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/","name":"Hundreds of GoDaddy Hosted Websites got infected by Backdoor","isPartOf":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#primaryimage"},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg","datePublished":"2022-03-21T12:44:03+00:00","description":"Hundreds of websites hosted on GoDaddy\u2019s Managed WordPress hosting services got infected by Backdoor malware","breadcrumb":{"@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#primaryimage","url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg","contentUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/03\/GoDaddy-Hosted-Websites-got-infected-1.jpg","width":1200,"height":675,"caption":"GoDaddy Hosted Websites got infected"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hostingseekers.com\/blog\/godaddy-hosted-websites-got-infected-by-backdoor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hostingseekers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Hundreds of GoDaddy Hosted Websites are infected by Backdoor Malware in a Single Day"}]},{"@type":"WebSite","@id":"https:\/\/www.hostingseekers.com\/blog\/#website","url":"https:\/\/www.hostingseekers.com\/blog\/","name":"Hostingseekers","description":"Hostingseekers","publisher":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hostingseekers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hostingseekers.com\/blog\/#organization","name":"HostingSeekers Pvt. Ltd.","url":"https:\/\/www.hostingseekers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2025\/04\/Hosting-Seekers-Logo.png","contentUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2025\/04\/Hosting-Seekers-Logo.png","width":451,"height":520,"caption":"HostingSeekers Pvt. Ltd."},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/hostingseekers","https:\/\/x.com\/Hostingseekers1","https:\/\/www.linkedin.com\/company\/hostingseekers\/","https:\/\/www.instagram.com\/hostingseekers\/"]},{"@type":"Person","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/person\/76bc9258cab3c5bfe0237d3e290b13ea","name":"manvinder Singh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","caption":"manvinder Singh"},"description":"Manvinder Singh is the Founder and CEO of HostingSeekers, an award-winning go-to-directory for all things hosting. Our team conducts extensive research to filter the top solution providers, enabling visitors to effortlessly pick the one that perfectly suits their needs. We are one of the fastest growing web directories, with 500+ global companies currently listed on our platform.","sameAs":["https:\/\/www.hostingseekers.com","https:\/\/www.linkedin.com\/in\/manvinder-singh\/"],"url":"https:\/\/www.hostingseekers.com\/blog\/author\/seodeveloper\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/9116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/comments?post=9116"}],"version-history":[{"count":3,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/9116\/revisions"}],"predecessor-version":[{"id":9121,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/9116\/revisions\/9121"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/media\/9154"}],"wp:attachment":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/media?parent=9116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/categories?post=9116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/tags?post=9116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}