{"id":1664,"date":"2026-05-01T14:23:16","date_gmt":"2026-05-01T14:23:16","guid":{"rendered":"https:\/\/www.mogacode.ma\/21-sites-wordpress-infectes-nuit\/"},"modified":"2026-05-23T14:35:44","modified_gmt":"2026-05-23T14:35:44","slug":"21-sites-wordpress-infectes-nuit","status":"publish","type":"post","link":"https:\/\/www.mogacode.ma\/en\/21-sites-wordpress-infectes-nuit\/","title":{"rendered":"21 sites WordPress infect\u00e9s en une nuit \u2014 retour d&rsquo;exp\u00e9rience MogaCode"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1664\" class=\"elementor elementor-1664 elementor-bc-flex-widget\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-sec_a3f7246 elementor-section-stretched elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"sec_a3f7246\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;stretch_section&quot;:&quot;section-stretched&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-col_fff4177\" data-id=\"col_fff4177\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-htm_ace4b03 elementor-widget elementor-widget-html\" data-id=\"htm_ace4b03\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t\t<style>\n.mg-article *{box-sizing:border-box;margin:0;padding:0}\n.mg-article{font-family:-apple-system,BlinkMacSystemFont,'Inter','Segoe UI',sans-serif;background:#0f0f0f;color:#f0f0f0;line-height:1.6}\n.mg-article .article-header{padding:80px 24px 48px;background:#0f0f0f;max-width:800px;margin:0 auto}\n.mg-article .article-meta{color:#888;font-size:0.875rem;margin-bottom:16px;letter-spacing:0.02em}\n.mg-article .article-meta span{display:inline-block;margin-right:16px}\n.mg-article .article-title{font-size:2.5rem;font-weight:800;line-height:1.2;margin-bottom:24px;color:#f0f0f0}\n.mg-article .article-lead{font-size:1.2rem;color:#ccc;line-height:1.6;border-left:4px solid #FF6B35;padding-left:20px}\n.mg-article .article-body{max-width:800px;margin:0 auto;padding:48px 24px}\n.mg-article .article-body h2{font-size:1.75rem;font-weight:700;margin:48px 0 16px;color:#f0f0f0}\n.mg-article .article-body h3{font-size:1.3rem;font-weight:600;margin:32px 0 12px;color:#FF6B35}\n.mg-article .article-body p{margin-bottom:20px;line-height:1.8;color:#d0d0d0}\n.mg-article .article-body ul,.mg-article .article-body ol{padding-left:24px;margin-bottom:20px}\n.mg-article .article-body li{margin-bottom:8px;line-height:1.7;color:#d0d0d0}\n.mg-article .article-body blockquote{border-left:4px solid #FF6B35;padding:16px 24px;background:#1a1a1a;margin:32px 0;font-style:italic;color:#ccc;border-radius:0 8px 8px 0}\n.mg-article .highlight-box{background:#1a1a1a;border:1px solid #2a2a2a;border-radius:8px;padding:24px;margin:32px 0}\n.mg-article .highlight-box h3{margin-top:0;color:#FF6B35}\n.mg-article .code-block{background:#111;border:1px solid #2a2a2a;border-radius:8px;padding:20px;font-family:monospace;font-size:0.875rem;color:#a8ff78;overflow-x:auto;margin:24px 0;white-space:pre}\n.mg-article .inline-cta{background:linear-gradient(135deg,#FF6B35,#e85a20);border-radius:8px;padding:32px;text-align:center;margin:48px 0}\n.mg-article .inline-cta h3{color:#fff;margin-bottom:12px;font-size:1.5rem;margin-top:0}\n.mg-article .inline-cta p{color:rgba(255,255,255,0.85);margin-bottom:24px}\n.mg-article .btn-white{display:inline-block;background:#fff;color:#FF6B35;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .author-box{display:flex;gap:16px;align-items:center;background:#1a1a1a;border-radius:8px;padding:24px;margin:48px 0;border:1px solid #2a2a2a}\n.mg-article .author-avatar{width:64px;height:64px;border-radius:50%;background:#FF6B35;display:flex;align-items:center;justify-content:center;font-size:1.5rem;font-weight:800;color:#fff;flex-shrink:0}\n.mg-article .author-info h4{margin:0 0 4px;font-size:1rem;font-weight:600;color:#f0f0f0}\n.mg-article .author-info p{margin:0;color:#888;font-size:0.875rem}\n.mg-article .article-cta-bottom{background:#141414;padding:64px 24px;text-align:center;border-top:1px solid #2a2a2a}\n.mg-article .article-cta-bottom h2{font-size:1.75rem;font-weight:700;margin-bottom:16px;color:#f0f0f0}\n.mg-article .article-cta-bottom p{color:#888;max-width:560px;margin:0 auto 28px;line-height:1.7}\n.mg-article .btn-orange{display:inline-block;background:#FF6B35;color:#fff;font-weight:700;padding:14px 28px;border-radius:6px;text-decoration:none;font-size:1rem}\n.mg-article .timeline{border-left:2px solid #2a2a2a;padding-left:24px;margin:32px 0}\n.mg-article .timeline-item{position:relative;margin-bottom:32px}\n.mg-article .timeline-item::before{content:'';position:absolute;left:-31px;top:6px;width:12px;height:12px;border-radius:50%;background:#FF6B35;border:2px solid #0f0f0f}\n.mg-article .timeline-time{font-size:0.8rem;font-weight:700;color:#FF6B35;text-transform:uppercase;letter-spacing:0.05em;margin-bottom:4px}\n.mg-article .timeline-item p{margin-bottom:0;color:#d0d0d0}\n.mg-article .stat-grid{display:grid;grid-template-columns:repeat(auto-fit,minmax(160px,1fr));gap:16px;margin:32px 0}\n.mg-article .stat-card{background:#1a1a1a;border:1px solid #2a2a2a;border-radius:8px;padding:20px;text-align:center}\n.mg-article .stat-card .stat-value{font-size:2rem;font-weight:800;color:#FF6B35;display:block;line-height:1}\n.mg-article .stat-card .stat-label{font-size:0.8rem;color:#888;margin-top:8px;display:block}\n<\/style>\n\n<div class=\"mg-article\">\n  <div class=\"article-header\">\n    <div class=\"article-meta\">\n      <span>WordPress Security<\/span>\n      <span>April 22, 2026<\/span>\n      <span>Reading time: 11 min<\/span>\n    <\/div>\n    <h1 class=\"article-title\">21 Infected WordPress Sites in One Night: MogaCode&#039;s Experience Report<\/h1>\n    <p class=\"article-lead\">During the night of April 21-22, 2026, 21 client websites hosted on MogaCode&#039;s main Infomaniak account were simultaneously compromised. Here is the full story\u2014attack vector, cleanup method, 14 backdoors removed, and the lessons learned.<\/p>\n  <\/div>\n\n  <div class=\"article-body\">\n\n    <div class=\"stat-grid\">\n      <div class=\"stat-card\">\n        <span class=\"stat-value\">21<\/span>\n        <span class=\"stat-label\">Infected sites<\/span>\n      <\/div>\n      <div class=\"stat-card\">\n        <span class=\"stat-value\">14<\/span>\n        <span class=\"stat-label\">Backdoors identified<\/span>\n      <\/div>\n      <div class=\"stat-card\">\n        <span class=\"stat-value\">12pm<\/span>\n        <span class=\"stat-label\">To clean everything<\/span>\n      <\/div>\n      <div class=\"stat-card\">\n        <span class=\"stat-value\">0<\/span>\n        <span class=\"stat-label\">Client reports an incident<\/span>\n      <\/div>\n    <\/div>\n\n    <h2>The Discovery \u2014 2 a.m.<\/h2>\n    <p>It all starts with a Wordfence alert on a first site. An unknown PHP file has just been modified in wp-content\/plugins\/. Upon opening the file, the signature is immediate: an obfuscated block of code with a recurring string \u2014 <code style=\"background:#222;padding:2px 6px;border-radius:3px;font-family:monospace;color:#a8ff78\">cAT3VWynuiL7CRgr<\/code>.<\/p>\n    <p>By cross-referencing this signature across other sites belonging to the same Infomaniak account, the conclusion is undeniable: 21 out of 21 sites contain the same pattern. The infection is systematic, methodical, and dates back several weeks.<\/p>\n\n    <h2>The attack vector \u2014 null plugins<\/h2>\n    <p>The investigation quickly traced the problem back to its source. The plugins in question are all &quot;null&quot; (cracked) versions of premium WordPress plugins:<\/p>\n    <ul>\n      <li><strong>Elementor Pro<\/strong> \u2014 null version, downloaded from an unofficial repository<\/li>\n      <li><strong>Ultimate Elementor (EU)<\/strong> \u2014 same origin<\/li>\n      <li><strong>RevSlider<\/strong> \u2014 backdoor included in the activation code<\/li>\n    <\/ul>\n\n    <blockquote>\n      A useless plugin is never free. The &quot;price&quot; you pay is a persistent backdoor waiting for instructions. The hacker activates the payload when they decide\u2014not during installation.\n    <\/blockquote>\n\n    <p>In our case, the backdoor had been dormant for weeks. Activation occurred simultaneously on all sites on the same evening, likely via an automated request to each compromised installation.<\/p>\n\n    <h2>Cleanup operation \u2014 the night of April 22<\/h2>\n\n    <div class=\"timeline\">\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">02:15 \u2014 Detection<\/div>\n        <p>First Wordfence alert. Identification of the signature cAT3VWynuiL7CRgr on the first site. Scan launched on all sites of the account.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">02:40 \u2014 Mapping<\/div>\n        <p>21 confirmed infected sites. SSH connection to the Infomaniak server. Recursive grep on the entire account to list all compromised files.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">03:00 \u2014 Isolation<\/div>\n        <p>The most critical sites (e-commerce, contact forms) are being put into maintenance mode. No customer will be notified of any incident \u2014 the cleanup will be seamless.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">03:30 \u2014 Serial cleaning<\/div>\n        <p>Systematic removal of each backdoor. On some sites, up to 3 separate infected files. On the CRM (crm.coden.lu), 14 individual backdoors and a 485 MB archive of exfiltrated data were found.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">05:00 \u2014 Reinstalling cores<\/div>\n        <p>Replacement of all WordPress core files on all 21 sites. Removal of all useless plugins. Installation of official versions.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">08:00 \u2014 Hardening<\/div>\n        <p>Rotate all passwords (WP, database, FTP). Regenerate WordPress security keys. Activate Wordfence Premium on all sites. Review file permissions.<\/p>\n      <\/div>\n      <div class=\"timeline-item\">\n        <div class=\"timeline-time\">2:00 PM \u2014 Production resumed<\/div>\n        <p>All 21 sites have been cleaned, hardened, and brought back online. No customer data was lost. The longest service interruption was 4 hours at a single site.<\/p>\n      <\/div>\n    <\/div>\n\n    <h2>The CRM case \u2014 the most critical<\/h2>\n    <p>Our internal CRM (Perfex, hosted by Infomaniak) was the most severely affected site. 14 individual backdoors had been deployed, and a 485 MB archive was being exfiltrated to an external server at the time of detection.<\/p>\n    <p>The exfiltration was interrupted before completion. Analysis of the contents of the (partially recovered) archive shows that it mainly contained database exports and configuration files.<\/p>\n    <p>All credentials were immediately invalidated and regenerated. Customers were proactively notified of the access reset via WhatsApp\u2014without mentioning the incident, through a planned maintenance communication.<\/p>\n\n    <div class=\"highlight-box\">\n      <h3>What we found in the infected files<\/h3>\n      <p style=\"color:#ccc;margin-bottom:16px\">Three recurring patterns in backdoors:<\/p>\n      <ul>\n        <li><strong>Eval + base64_decode<\/strong> \u2014 execution of remote code encoded in base64, almost invisible in a large PHP file<\/li>\n        <li><strong>Remote Shell<\/strong> \u2014 SSH-like access from a browser, allowing the execution of system commands<\/li>\n        <li><strong>Cache file uploader<\/strong> \u2014 a POST form accepting any file, disguised as a real plugin script<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"inline-cta\">\n      <h3>Are you using useless plugins?<\/h3>\n      <p>Have your installation audited now. A backdoor can be present for months without any visible symptoms.<\/p>\n      <a href=\"https:\/\/www.mogacode.ma\/en\/audit-gratuit\/\" class=\"btn-white\">Request a free audit<\/a>\n    <\/div>\n\n    <h2>The lessons \u2014 what we have changed<\/h2>\n\n    <h3>1. Zero tolerance for useless plugins<\/h3>\n    <p>This is the most obvious lesson, yet the most ignored. A premium plugin costs \u20ac50 to \u20ac200 per year. An infection of this type costs dozens of hours of work, poses GDPR risks, and potentially damages your customers&#039; trust. The math doesn&#039;t add up.<\/p>\n\n    <h3>2. Active monitoring at each site<\/h3>\n    <p>Before this incident, Wordfence was installed on some sites but not all. Since then, every MogaCode site has Wordfence Premium active with daily scans and immediate alerts in case of file modifications.<\/p>\n\n    <h3>3. Separation of hosting accounts<\/h3>\n    <p>Having 21 sites on the same Infomaniak account is convenient for management\u2014but disastrous in case of infection. We have since migrated some sites to isolated accounts. A compromise on one account must no longer be able to infect neighboring accounts.<\/p>\n\n    <h3>4. Daily off-server backup<\/h3>\n    <p>Infomaniak backups exist but remain on the same server. We have implemented automatic daily backups to independent S3 storage. If the server is compromised, the backups are not.<\/p>\n\n    <h3>5. Security keys and passwords should be rotated periodically.<\/h3>\n    <p>We&#039;ve adopted a quarterly rotation of WordPress security keys and database passwords across all managed sites. This isn&#039;t industry standard\u2014but after tonight, it&#039;s our standard.<\/p>\n\n    <div class=\"highlight-box\">\n      <h3>Post-incident checklist \u2014 what we now check at each site<\/h3>\n      <ul>\n        <li>All plugins come from the official WordPress.org repository or the publisher&#039;s website \u2014 never from a third-party source<\/li>\n        <li>Wordfence Premium active with daily scan and email alerts + WhatsApp<\/li>\n        <li>No unknown administrator accounts in the WP user list<\/li>\n        <li>No PHP files in wp-content\/uploads\/<\/li>\n        <li>WordPress security keys regenerated within the last 6 months<\/li>\n        <li>Database password different from FTP password, different from WP password<\/li>\n        <li>Off-server backup tested and restoreable<\/li>\n      <\/ul>\n    <\/div>\n\n    <div class=\"author-box\">\n      <div class=\"author-avatar\">P<\/div>\n      <div class=\"author-info\">\n        <h4>Patrick Rary<\/h4>\n        <p>Fondateur MogaCode \u2014 Ing\u00e9nieur informaticien. Cette nuit du 22 avril 2026 a conduit MogaCode a revoir entierement ses standards de securite pour tous ses sites geres.<\/p>\n      <\/div>\n    <\/div>\n\n  <\/div>\n\n  <div class=\"article-cta-bottom\">\n    <h2>MogaCode Care \u2014 security that never sleeps<\/h2>\n    <p>Active monitoring, updates, off-server backups, and incident response. So you never have to experience that kind of night again.<\/p>\n    <a href=\"https:\/\/www.mogacode.ma\/en\/sites-wordpress\/\" class=\"btn-orange\">Discover MogaCode Care<\/a>\n  <\/div>\n<\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>En avril 2026, 21 sites clients ont \u00e9t\u00e9 compromis simultan\u00e9ment par une faille critique du plugin Unlimited Elements. Retour terrain sur la d\u00e9tection, le nettoyage et les le\u00e7ons retenues.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,16],"tags":[],"class_list":["post-1664","post","type-post","status-publish","format-standard","hentry","category-s-curit-wordpress","category-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v28.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>21 Sites WordPress Infect\u00e9s en une Nuit \u2014 Retour d&#039;Exp\u00e9rience MogaCode<\/title>\n<meta name=\"description\" content=\"En avril 2026, 21 sites WordPress que nous g\u00e9rons ont \u00e9t\u00e9 compromis simultan\u00e9ment via une faille critique d&#039;un plugin Elementor l\u00e9gitime. Voici comment on a tout nettoy\u00e9 en 48h.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mogacode.ma\/en\/21-sites-wordpress-infectes-nuit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"21 sites WordPress infect\u00e9s en une nuit \u2014 retour d&#039;exp\u00e9rience MogaCode\" \/>\n<meta property=\"og:description\" content=\"En avril 2026, 21 sites WordPress que nous g\u00e9rons ont \u00e9t\u00e9 compromis simultan\u00e9ment via une faille critique d&#039;un plugin Elementor l\u00e9gitime. Voici comment on a tout nettoy\u00e9 en 48h.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mogacode.ma\/en\/21-sites-wordpress-infectes-nuit\/\" \/>\n<meta property=\"og:site_name\" content=\"Mogacode\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/mogacode\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-01T14:23:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-23T14:35:44+00:00\" \/>\n<meta name=\"author\" content=\"Patrick\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mogacode\" \/>\n<meta name=\"twitter:site\" content=\"@mogacode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Patrick\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"21 Sites WordPress Infect\u00e9s en une Nuit \u2014 Retour d'Exp\u00e9rience MogaCode","description":"En avril 2026, 21 sites WordPress que nous g\u00e9rons ont \u00e9t\u00e9 compromis simultan\u00e9ment via une faille critique d'un plugin Elementor l\u00e9gitime. Voici comment on a tout nettoy\u00e9 en 48h.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mogacode.ma\/en\/21-sites-wordpress-infectes-nuit\/","og_locale":"en_US","og_type":"article","og_title":"21 sites WordPress infect\u00e9s en une nuit \u2014 retour d'exp\u00e9rience MogaCode","og_description":"En avril 2026, 21 sites WordPress que nous g\u00e9rons ont \u00e9t\u00e9 compromis simultan\u00e9ment via une faille critique d'un plugin Elementor l\u00e9gitime. Voici comment on a tout nettoy\u00e9 en 48h.","og_url":"https:\/\/www.mogacode.ma\/en\/21-sites-wordpress-infectes-nuit\/","og_site_name":"Mogacode","article_publisher":"https:\/\/www.facebook.com\/mogacode","article_author":"https:\/\/www.facebook.com\/mogacode","article_published_time":"2026-05-01T14:23:16+00:00","article_modified_time":"2026-05-23T14:35:44+00:00","author":"Patrick","twitter_card":"summary_large_image","twitter_creator":"@mogacode","twitter_site":"@mogacode","twitter_misc":{"Written by":"Patrick","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[]}},"_links":{"self":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/comments?post=1664"}],"version-history":[{"count":6,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1664\/revisions"}],"predecessor-version":[{"id":1784,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/posts\/1664\/revisions\/1784"}],"wp:attachment":[{"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/media?parent=1664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/categories?post=1664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mogacode.ma\/en\/wp-json\/wp\/v2\/tags?post=1664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}