Skip to content
Mohammad Emmon Mohammad Emmon.

Malware Removal & Security

Joshua David Plumbing

Recurring WordPress malware traced to the trigger rebuilding the attacker’s admin

Delivered by Mohammad Emmon
01

The problem

The plumbing company's site was quietly running a casino-spam and Googlebot-cloaking framework: a malicious WPCode snippet disguised as “Completely Disable Comments” that hid spam authors, injected scripts, and showed search engines a different site than real visitors saw. A hidden rogue admin, a Tiny File Manager web-shell tucked inside the theme, and staged web-shell payloads rounded out the picture — and it had been “cleaned” before, only to come back.

02

What I did

  • Ran a full database and file forensic pass, confirming the WPCode backdoor, the cloaking configuration (a list of Google IP ranges), 100 blocks of injected casino spam, and the rogue admin.
  • Found the file-side backdoors: a 185KB Tiny File Manager web-shell hidden in the theme and a cluster of staged PHP-exec payloads, and reconstructed the true patient-zero date from file timestamps.
  • During verification, uncovered the reinfection mechanism — a malicious MySQL trigger that re-created the rogue admin from a booby-trapped comment — and confirmed it was gone across three successive database exports.
  • Built and delivered a custom hardening must-use plugin (rogue-admin auto-block, trigger tripwire, upload/option scanning, alerts) plus a root .htaccess ruleset and install guide.
03

The result

The engagement closed fully clean: no rogue admin, all malware signatures at zero, file backdoors deleted, and the self-healing trigger eliminated. On top of a verified-clean site, the client walked away with a bespoke security plugin actively guarding against exactly the techniques that had been used against them, and server-side hardening (rotated credentials, least-privilege database user) done by their host.

Recurring WordPress malware traced to the trigger rebuilding the attacker’s admin
04

What it proves

Recurring WordPress malware is never bad luck — you don't mop it up, you find why it keeps coming back. Here that meant a database trigger, and then a custom plugin built to watch for it happening again.

Mohammad Emmon

Delivered by

Mohammad Emmon

WordPress Malware Removal, Security, Ongoing Security Monitoring And Website Development

I'm a WordPress malware removal and security specialist — I've cleaned and secured over 10,000 sites. Once a site is safe, I can also build, run and automate the whole thing. Based in Dhaka, working worldwide.

  • 15,000+ sites secured
  • 745+ businesses
  • 96% come back

Worried about your site?

Think your WordPress site is hacked? Let's check it.