Skip to content
Mohammad Emmon Mohammad Emmon.

Malware Removal & Security

Loans in Namibia

A rogue WordPress admin holding five live foreign-IP sessions — attacker still inside

Delivered by Mohammad Emmon
01

The problem

This lending site had a rogue administrator account — named “admlnlx” to be misread as “admin” at a glance — that wasn't just sitting there: it held five live login sessions from several different foreign IP addresses, direct evidence the attacker was actively using it. Backing it up were a fake active backdoor plugin and four dormant “protect-uploads” droppers staged in randomly-named folders, a classic self-healing arrangement built to survive a partial cleanup.

02

What I did

  • Confirmed the rogue admin from the raw user tables — its disguised name, misspelled “wordpress” email, five concurrent foreign-IP sessions, and attacker-created metadata — as the single highest-priority item.
  • Identified the fake active plugin and the four dormant redundant droppers from WordPress's own plugin-update transient, matching them to a documented backdoor-dropper family.
  • Verified the reassuring part honestly: post content, cron schedule, and core URLs were all clean, so the problem was bounded to the access layer where reinfection originates.
  • Was explicit about scope limits — a database-only export can't prove the entry vector — and set out the ranked probable vectors plus exactly what evidence (files + logs) would confirm it.
03

The result

The client got an unambiguous verdict and a priority-ordered plan: kill the rogue admin and its live sessions first, remove all five backdoor plugins, rotate every credential, then supply files and logs so the entry point could be confirmed rather than inferred. The honesty about what a DB-only scan can and cannot prove kept the remediation grounded in evidence.

A rogue WordPress admin holding five live foreign-IP sessions — attacker still inside
04

What it proves

A rogue WordPress admin holding five live sessions from foreign IPs is not a historical breach — it is someone logged in right now. That changes the order you do everything in.

Mohammad Emmon

Delivered by

Mohammad Emmon

WordPress Malware Removal, Security, Ongoing Security Monitoring And Website Development

I'm a WordPress malware removal and security specialist — I've cleaned and secured over 10,000 sites. Once a site is safe, I can also build, run and automate the whole thing. Based in Dhaka, working worldwide.

  • 15,000+ sites secured
  • 745+ businesses
  • 96% come back

Worried about your site?

Think your WordPress site is hacked? Let's check it.