Hackers abuse Google ads for GoDaddy ManageWP login phishing
Block the malicious Google Ads result for the 'managewp' query and verify that your ManageWP login redirects to the official domain, preventing credential theft.
Block the malicious Google Ads result for the 'managewp' query and verify that your ManageWP login redirects to the official domain, preventing credential theft.
Summary
A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites. The threat actor uses an adversary‑in‑the‑middle (AiTM) approach, where the fake login page acts as a real‑time proxy between the victim and the legitimate ManageWP service, capturing credentials and then using them to log in and request the two‑factor authentication code.
Guardio Labs discovered that the malicious result appears above the real ManageWP search result for the query "managewp", luring users who rely on Google to find the URL for logging in. The attackers send the credentials to a Telegram channel and then log in to the victim’s account in real time, exploiting the fact that each ManageWP account typically hosts hundreds of sites. The campaign includes a Russian‑language agreement, a C2 panel with a dropdown command system, and has already infected 200 unique victims.
ManageWP’s plugin is active on more than 1 million WordPress sites, making this a widespread threat. Guardio Labs has captured victim data and is alerting users to the exposure. The incident demonstrates a sophisticated phishing technique that bypasses simple credential capture by actively logging in and requesting 2FA, highlighting the need for stricter verification of login URLs and monitoring of Google Ads results.
Key changes
- Phishing campaign uses Google Ads to display a fake ManageWP login above the real result
- Attack employs adversary‑in‑the‑middle to proxy credentials to the attacker
- Captured credentials are used to log in real ManageWP account and request 2FA code
- 200 unique victims identified and Guardio Labs alerted them
- C2 panel includes a dropdown command system and Russian‑language agreement
- ManageWP plugin active on >1 million WordPress sites
- Attack uses live AiTM rather than static credential capture
- Guardio Labs captured victim data and is monitoring the C2 infrastructure