OffPerimeter · Threat advisories
Campaign advisory
mediumPublished 2026-09-23 · 5 indicators

ClickFix backdoor distributed via Brevo supply-chain attack on WordPress sites

A supply-chain attack on Brevo compromised a Cloudflare API key, allowing attackers to inject malicious ClickFix scripts into customer websites. The attack affected Brevo's domains and embedded scripts, leading to the distribution of a malicious WordPress plugin named 'Web Media Optimizer' that acts as a backdoor. The plugin communicates with an attacker-controlled server and can generate valid login sessions for WordPress administrators. The attack was active between September 14 and 15, 2026, and affected up to 100,000 websites.

ShareXLinkedInWhatsApp
First seen
2026-09-14
Last seen
2026-09-17
Threat actors
—
Malware
ClickFix, Web Media Optimizer
Sectors
Technology
Countries
United States

How it works

Attackers compromised a Cloudflare API key, enabling them to inject malicious ClickFix scripts into Brevo's customer websites. These scripts were used to distribute a malicious WordPress plugin named 'Web Media Optimizer,' which acts as a backdoor. The plugin communicates with an attacker-controlled server and can generate valid login sessions for WordPress administrators, allowing further access and control.

Techniques (MITRE ATT&CK)

Indicators

Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.

Domains (4)
  • glegchner.com
  • cdn10.sendibt1.com
  • yelahaye.surf
  • boiseno.club
URLs (1)
  • https://cdn10.sendibt1.com/p/wm.zip

What to do

References

ShareXLinkedInWhatsApp