Cybersecurity Alert: Phishing Attack Targets ManageWP Users via Google Ads
A recent phishing campaign is exploiting Google Ads to deceive users of ManageWP, a popular platform for managing multiple WordPress sites. Cybercriminals have created a fake login page that appears legitimate, utilizing a method known as adversary-in-the-middle (AitM) to capture user credentials in real-time.
The attack affects web developers, agencies, and enterprises using ManageWP, which manages over 1 million websites. Victims searching for the login page may unknowingly click on a malicious Google search result, leading them to a counterfeit site where their credentials are sent directly to the attackers. Once logged in, victims are prompted to provide a two-factor authentication code, giving attackers full access to their accounts.
To protect yourself, always verify web addresses and enable multi-factor authentication when possible. Be cautious of unusual login prompts.
Risk Level: High
Source: View Original Report
