
Lab539 Uncovers WordPress Campaign Utilizing PowerShell RAT to Target Entities
Executive Summary Researchers from Lab539 on 12 August 2026 observed a widespread campaign utilizing compromised WordPress sites to deliver a ClickFix verification flow that prompts users to execute a malicious PowerShell command. The injected JavaScript employs an EtherHiding mechanism, retrieving AES-encrypted code from an Ethereum smart contract on the Sepolia network rather than hardcoding the payload...