Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-05-05
Updated
2026-08-28

ATT&CK techniques

Initial Access → Exfiltration
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects HTTP POST requests to the path /wp-includes/ms-menu.php, a fake WordPress endpoint used by the SilentSelfie watering hole campaign to receive stolen geolocation, WebRTC IP and webcam selfie data from visitors of compromised Kurdish websites. The ms-menu.php filename does not exist in genuine WordPress installations. Traffic to it indicates victim data exfiltration.

Related detections9 linkedT1041 — drag to rearrange
Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
Malicious Vice Society Directory Crawling Script for Data Exfiltration - Via Ps_script (via ps_script)
Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious DEEPPOST Data Exfiltration URI Pattern via BrazenBamboo
Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)
Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.