21 Infected WordPress Sites in One Night: MogaCode's Experience Report
Dans la nuit du 21 au 22 avril 2026, 21 sites clients heberges sur le compte Infomaniak principal de MogaCode ont ete compromis simultanement. Voici le recit complet, vecteur d'attaque, methode de nettoyage, 14 backdoors supprimees, et les lecons que nous en avons tirees.
La decouverte, 2h du matin
Tout commence par une alerte Wordfence sur un premier site. Un fichier PHP inconnu vient d'etre modifie dans wp-content/plugins/. En ouvrant le fichier, la signature est immediate : un bloc de code obfusque avec une chaine recurrente, cAT3VWynuiL7CRgr.
By cross-referencing this signature across other sites belonging to the same Infomaniak account, the conclusion is undeniable: 21 out of 21 sites contain the same pattern. The infection is systematic, methodical, and dates back several weeks.
Le vecteur d'attaque, plugins nulles
The investigation quickly traced the problem back to its source. The plugins in question are all "null" (cracked) versions of premium WordPress plugins:
- Elementor Pro, version nullee, telecharge depuis un depot non officiel
- Ultimate Elementor (EU), meme origine
- RevSlider, backdoor incluse dans le code d'activation
Un plugin nulle n'est jamais gratuit. Le "prix" que vous payez, c'est une backdoor persistante qui attend ses instructions. Le hacker active la charge utile quand il le decide, pas au moment de l'installation.
In our case, the backdoor had been dormant for weeks. Activation occurred simultaneously on all sites on the same evening, likely via an automated request to each compromised installation.
Deroulement du nettoyage, la nuit du 22 avril
First Wordfence alert. Identification of the signature cAT3VWynuiL7CRgr on the first site. Scan launched on all sites of the account.
21 confirmed infected sites. SSH connection to the Infomaniak server. Recursive grep on the entire account to list all compromised files.
Les sites les plus critiques (e-commerce, formulaires de contact) passent en maintenance. Aucun client ne sera notifie d'un incident, le nettoyage sera transparent.
Systematic removal of each backdoor. On some sites, up to 3 separate infected files. On the CRM (crm.coden.lu), 14 individual backdoors and a 485 MB archive of exfiltrated data were found.
Replacement of all WordPress core files on all 21 sites. Removal of all useless plugins. Installation of official versions.
Rotate all passwords (WP, database, FTP). Regenerate WordPress security keys. Activate Wordfence Premium on all sites. Review file permissions.
All 21 sites have been cleaned, hardened, and brought back online. No customer data was lost. The longest service interruption was 4 hours at a single site.
Le cas CRM, le plus critique
Our internal CRM (Perfex, hosted by Infomaniak) was the most severely affected site. 14 individual backdoors had been deployed, and a 485 MB archive was being exfiltrated to an external server at the time of detection.
The exfiltration was interrupted before completion. Analysis of the contents of the (partially recovered) archive shows that it mainly contained database exports and configuration files.
Toutes les credentials ont ete immediatement invalidees et regenerees. Les clients ont ete proactivement informes de la reinitialisation de leurs acces via WhatsApp, sans mentionner l'incident, par une communication de maintenance planifiee.
What we found in the infected files
Three recurring patterns in backdoors:
- Eval + base64_decode, execution de code distant encode en base64, presque invisible dans un fichier PHP volumineux
- Remote Shell, acces SSH-like depuis un navigateur, permettant d'executer des commandes systeme
- Cache file uploader, formulaire POST acceptant n'importe quel fichier, camouffle dans un vrai script de plugin
Are you using useless plugins?
Have your installation audited now. A backdoor can be present for months without any visible symptoms.
Request a free auditLes lecons, ce que nous avons change
1. Zero tolerance for useless plugins
This is the most obvious lesson, yet the most ignored. A premium plugin costs €50 to €200 per year. An infection of this type costs dozens of hours of work, poses GDPR risks, and potentially damages your customers' trust. The math doesn't add up.
2. Active monitoring at each site
Before this incident, Wordfence was installed on some sites but not all. Since then, every MogaCode site has Wordfence Premium active with daily scans and immediate alerts in case of file modifications.
3. Separation of hosting accounts
21 sites sur le meme compte Infomaniak, c'est pratique pour la gestion, et catastrophique en cas d'infection. Nous avons depuis migre certains sites vers des comptes isoles. Un compromis sur un compte ne doit plus pouvoir contaminer les voisins.
4. Daily off-server backup
Infomaniak backups exist but remain on the same server. We have implemented automatic daily backups to independent S3 storage. If the server is compromised, the backups are not.
5. Security keys and passwords should be rotated periodically.
Nous avons adopte une rotation trimestrielle des security keys WordPress et des mots de passe de base de donnees sur tous les sites geres. Ce n'est pas standard dans l'industrie, mais apres cette nuit, c'est notre standard.
Checklist post-incident, ce que nous verifions maintenant sur chaque site
- Tous les plugins viennent du depot officiel WordPress.org ou du site de l'editeur, jamais d'une source tierce
- Wordfence Premium active with daily scan and email alerts + WhatsApp
- No unknown administrator accounts in the WP user list
- No PHP files in wp-content/uploads/
- WordPress security keys regenerated within the last 6 months
- Database password different from FTP password, different from WP password
- Off-server backup tested and restoreable
Patrick Rary
Fondateur MogaCode, Expert judiciaire informaticien. Cette nuit du 22 avril 2026 a conduit MogaCode a revoir entierement ses standards de securite pour tous ses sites geres.
MogaCode Care, la securite qui ne dort pas
Active monitoring, updates, off-server backups, and incident response. So you never have to experience that kind of night again.
Discover MogaCode Care