A malware operation dubbed 'DollyWay' has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites. The campaign has evolved significantly in the past eight years, leveraging advanced evasion, re-infection, and monetization strategies. According to GoDaddy researcher Denis Sinegubko, DollyWay has been functioning as a large-scale scam redirection system in its latest version (v3). However, in the past, it has distributed more harmful payloads like ransomware and banking trojans. "GoDaddy Security researchers have uncovered evidence linking multiple malware campaigns into a single, long-running operation we've named 'DollyWay World Domination'," explains a recent report by Godaddy. "While previously thought to be separate campaigns, our research reveals these attacks share common infrastructure, code patterns, and monetization methods - all appearing to be connected to a single, sophisticated threat actor. "The operation was named after the following tell-tale string, which is found in some variations of the malware: define('DOLLY_WAY', 'World Domination')." DollyWay v3 is an advanced redirection operation that targets vulnerable WordPress sites using n-day flaws on plugins and themes to compromise them. As of February 2025, DollyWay generates 10 million fraudulent impressions per month by redirecting WordPress site visitors to fake dating, gambling, crypto, and sweepstakes sites. The campaign is monetized through VexTri...
Malware campaign 'DollyWay' breached 20,000 WordPress sites
BleepingComputer
·Bill Toulas
·Published Mar 19, 2025
·Updated
Affected Software
4 affected components
WordPress WordPress
WPCode WPCode
WordPress WordPress
GoDaddy DollyWay=v3
Frequently Asked Questions
1
What is the primary focus of the DollyWay malware campaign article?
The article discusses the DollyWay malware campaign that has compromised over 20,000 WordPress sites since 2016.
2
What are the main security concerns highlighted in the DollyWay campaign?
The campaign poses serious security risks by redirecting users from affected WordPress sites to malicious websites.
3
How long has the DollyWay malware campaign been active?
The DollyWay malware campaign has been active since 2016, evolving over an eight-year period.
4
What specific platforms are impacted by the DollyWay malware?
The malware primarily affects WordPress and WPCode platforms.
5
What companies are mentioned in association with the DollyWay malware?
GoDaddy is mentioned in relation to the DollyWay malware operation.