Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026

    The Leftist Split Over AI Doom

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech
    • The AI ‘Slowdown’ Is an Antitrust Mess
    • The Next Frontier Is Not Artificial Intelligence—It’s Artificial Societies
    • Here’s What the AI Apocalypse Could Look Like
    • The AI Slowdown Debate Crashed Salesforce’s Party
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers abuse Google ads for GoDaddy ManageWP login phishing
    Cybersecurity

    Hackers abuse Google ads for GoDaddy ManageWP login phishing

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 7, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers abuse Google ads for GoDaddy ManageWP login phishing
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites.

    The threat actor is using an adversary-in-the-middle (AitM) approach where the fake login page acts as a real-time proxy between the victim and the legitimate ManageWP service.

    ManageWP is a centralized remote administration platform for WordPress websites, enabling users to manage multiple sites from a single panel instead of logging into separate dashboards. Common users include web developers, web agencies managing client sites, and enterprises.

    Researchers at Guardio Labs warn that the fake result is displayed above the real one for the ‘managewp’ query, luring users who rely on Google to find the URL for logging into ManageWP.

    Malicious Google Search result
    Source: Guardio Labs

    Users clicking on the malicious result are taken to a login page that looks identical to the real one. However, any credentials typed in are delivered to a Telegram channel controlled by the attacker.

    Unlike the more common phishing pages that capture username and password pairs, the campaign uses a live AiTM setup, as the attacker uses the credentials to log into the platform in real-time.

    The victim is then served a fake prompt to enter the two-factor authentication (2FA) code, which the threat actor uses to gain access to the ManageWP account.

    Guardio Labs head researcher Nati Tal told BleepingComputer that each ManageWP account typically hosts hundreds of sites.

    According to WordPress.org stats, ManageWP’s plugin, which gives the platform control over registered sites, is active on more than 1 million websites.

    Guardio Labs was able to infiltrate the attacker’s command-and-control (C2) infrastructure and observed a dropdown command system that enables an interactive and operator-driven phishing flow.

    C2 panel
    Source: Guardio Labs

    Tal also said that the platform does not seem to be part of a commodity kit but rather a private phishing framework.

    Interestingly, the researcher found embedded in the code a Russian-language agreement, in which the author denounces responsibility for illegal activity, includes an educational/research use disclaimer, and prohibits public leaks of panel files or use against Russia-based systems.

    Guardio Labs has captured victim data from the attackers and started to contact victims to alert them about the exposure. The researchers have confirmed 200 unique victims at the time of writing.

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    abuse ads GoDaddy Google hackers login ManageWP Phishing
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads

    September 10, 2026

    Spirit Airlines Wants to Sell Its Data to Google. Former Flight Attendants Are Freaked Out

    August 25, 2026

    How to Disable Gemini in Gmail and Google Docs

    August 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    • The Download: AI’s extinction risk and bioweapons threat
    • The Leftist Split Over AI Doom
    • The specter of AI-enabled bioweapons is a wake-up call for biotech
    • The AI ‘Slowdown’ Is an Antitrust Mess

    AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race

    September 18, 2026

    The Download: AI’s extinction risk and bioweapons threat

    September 18, 2026

    The Leftist Split Over AI Doom

    September 18, 2026

    The specter of AI-enabled bioweapons is a wake-up call for biotech

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.