PhishWP: The Russian Scam Turning WordPress into a Cybercrime Circus
PhishWP is a malicious WordPress plug-in that turns sites into phishing traps. It mimics trusted payment services like Stripe to steal credit card details and more. Victims think they’re making secure payments, but their data goes straight to cybercriminals via Telegram. It’s like getting a receipt for a purchase you never made!

Hot Take:
Oh, WordPress, what have you become? Once a platform for blogging about cats and quinoa recipes, now a playground for Russian cyber villains. With PhishWP, the cybercriminals have gone full Dr. Evil by turning innocuous e-commerce checkout processes into a digital pickpocketing scheme. Shoppers, beware: that checkout button is not your friend!
Key Points:
- PhishWP is a malicious WordPress plug-in that turns sites into phishing pages.
- The plug-in convincingly impersonates legitimate checkout services like Stripe.
- It steals sensitive payment data and sends it to cybercriminals via Telegram.
- Features include OTP hijacking, browser profiling, and auto-response emails.
- PhishWP poses a significant threat due to its integration with the browser.
Already a member? Log in here