The Threat Landscape: An 8-Month Silent Infiltration
Apex Digital is an agile UK web design and digital agency managing an active estate of roughly 200 client WordPress websites. With a compact, dedicated team of designers and front-end developers, their focus has always been creating beautiful, high-performing websites that drive client growth.
Unbeknownst to their team, sophisticated threat actors had gained initial access nearly eight months prior through an unpatched vulnerability in an unmaintained third-party WordPress plugin. Rather than immediately defacing sites or triggering alarms, the attackers played a patient, stealthy long game: planting lightweight, obfuscated command-and-control (C2) backdoors across several client environments.
The hosting server was running a fully updated cPanel/WHM environment protected by ImunifyAV. Yet, despite current antivirus definitions, the malware maintained persistence undetected for over seven months. The botnet maintained a quiet, low-frequency heartbeat—checking in with remote command servers only once every two weeks to blend in with legitimate cron traffic and evade standard file-level scanners.
The Crisis: Automated Whack-a-Mole & The Mid-Week Cascade
Approaching a mid-week Thursday, the threat actors flipped the switch. The dormant network was remotely weaponized into an aggressive financial spam and botnet-bank-spam operation. Rogue landing pages, cloaked redirects, and spam-injection payloads detonated simultaneously, with exploiters gaining full wp-admin administrator control over the compromised installations.
When the agency’s internal team initially attempted to clean up the first reported site manually, they were caught in an automated trap: the botnet monitored its own payload, immediately pinged remote C2 servers upon deletion, and automatically reinstalled the malicious plugins within seconds.
Within hours, what started as an isolated complaint multiplied exponentially. Overnight, seven high-profile client websites were actively compromised and broadcasting bank spam. The agency founder was swamped with emergency calls from alarmed, angry business owners demanding answers as support phones rang off the hook.
Sysafe Services Deployed
The Sysafe Intervention: 1 Million Files Scanned & Complete Remediation
Facing a critical threat to their client relationships and reputation, Apex Digital called in Sysafe for emergency remediation. Our engineers mobilized instantly:
- Host Isolation Preserved: Crucially, due to previous Sysafe server hardening work (strict process jailing and per-user environment isolation), there was zero cross-account contamination. The infection was strictly quarantined to individual user directories where vulnerable software existed, preventing a catastrophic server-wide root compromise.
- Breaking the Automated Re-infection Loop: Sysafe severed the botnet’s C2 network sockets and process hooks, disabling the automatic plugin reinstallation mechanism before the attackers could maintain persistence.
- Deep 1-Million File Forensic Sweep: Our forensic pipeline scanned and processed over 1,000,000 files across the entire server estate. Active infections were strictly isolated to customer websites of the agency, where 7 client domains had been actively exploited. Crucially, the attackers never gained access to the agency’s internal redesign website—despite it running a very old WordPress version and being low-hanging fruit, it was luckily untouched. However, our scan uncovered 18 other domains across the fleet vulnerable to public CVEs (including the agency's primary site and that exposed redesign site), allowing us to patch and eliminate these sitting ducks before attackers could pivot.
- Full Production Recovery in 7 Hours: Sysafe systematically eradicated all rogue administrator accounts, sanitized malicious database injections, restored core files to verified clean checksums, and hardened all 25 domains. All seven hijacked client websites were returned to full, clean operational status within seven hours of engagement.
The Strategic Solution: Why Zero-Day WAF Was the Missing Link
This engagement highlighted a crucial reality for digital agencies: a secured WHM server and traditional host antivirus (like ImunifyAV) provide essential baseline isolation, but file scanners alone cannot prevent zero-days from penetrating or detect stealthy C2 backdoors that fly under the radar for months.
Furthermore, in an agency managing ~200 bespoke client websites, manually patching every plugin and theme is practically impossible. Every update requires client quotes, sign-offs, staging tests, and billable developer time. While waiting for approvals, client sites sit exposed.
To eliminate this systemic risk, Sysafe deployed our Managed Defence WAF with Zero-Day Virtual Patching across Apex Digital’s entire 200-site fleet. Our edge inspection engine now intercepts and neutralizes zero-day exploits and CVE attempts before malicious requests can ever touch PHP or reach WordPress application code—giving the agency instant, automated immunity across their entire client portfolio without needing code updates or client approvals.
Measurable Outcomes
The intervention turned an existential agency crisis into long-term infrastructure resilience:
- 7-Hour Rapid Recovery: Over 1,000,000 files processed, 7 exploited sites restored, and 18 vulnerable domains patched in under seven hours.
- Complete Agency Fleet Protection: All 200 client websites (plus the agency’s own site and legacy staging environments) are now proactively shielded by Managed Defence.
- Zero Update Friction: Virtual patching eliminates the client quote-and-approval bottleneck, stopping exploits at the edge without breaking bespoke client code.
- Client Retention: 100% of affected clients were retained, with zero reinfections or recurring alerts since deployment.
"When our client sites started broadcasting bank spam and the botnet kept reinstalling plugins faster than we could delete them, it was an absolute nightmare. Sysafe stepped in with total composure. They scanned over a million files, found backdoors that had escaped server antivirus for seven months, and had all seven sites clean and back online in seven hours. Deploying their Managed Defence WAF across our 200-site estate has completely changed our business—our clients are automatically protected from zero-days at the perimeter, and our dev team doesn't have to chase client quotes just to keep sites safe."— Mark Davies, Founder & Technical Lead, Apex Digital