-
A forum actor is seeking valid WordPress administrator access, with unique credentials and higher-traffic sites reportedly attracting more interest.
-
The buyer asks for a line format common in data taken by password-stealing malware.
-
The request highlights the growing value of stolen browser credentials and session data, which can give criminals access without exploiting a WordPress flaw.
A user in a Russian-speaking dark web forum is reportedly shopping for access keys to other people’s websites. In the newly surfaced underground market listing, the buyer says they want unique and working credentials for WordPress administrator login and admin pages.
The listing also places more value on websites with higher traffic. The buyer says they’ll check credentials before making payment. They may also ask for a small number of samples to test before completing a deal.
It’s worth noting that the request didn’t name any particular victim, specific website, company, or organization. So for now, the post remains just an unverified dark web market listing.
Details of the Listing
The buyer wants admin-level access that is “good,” with no “10 neighbors.” That means the login should not have been sold to many other people. Each one should be unique. Busy websites are a plus, according to the post.
Additionally, the buyer requires lines with web addresses, usernames, and passwords. They’ll run them through a checker, it is a tool for testing whether logins are valid. If the login passes this test, it can be sold. The price of the items will be negotiated privately. The price of the item is given as “0-2” without specifying any currency.
Two requirements of the buyer are declined logins and “CIS lines.” The buyer may also request five to ten samples at the beginning of the interaction to make sure the material meets their criteria. The profile is a seller and is registered in December 2024 with 74 posts.
There is a line below the post that indicates that the user is seeking work. There is nothing in the post that could prove the transaction took place. It is a request, not a purchase.
What WordPress Admin Access is Valuable
WordPress runs a large percentage (about 42.6%) of all websites, according to stats from W3Techs. That makes it a big target. An admin login lets a person install plugins, edit themes, and reach the site’s database. Hacked sites are then put to work. Attackers plant spam links, redirect visitors, and spread malware.
Traffic is likely the draw here. The attacker needs popular websites, and a network of attacks known as VexTrio exploited around 20,000 hacked WordPress sites to redirect users and make money from ads. In addition, some attackers use hacked sites to display fake verification pages containing the Lumma Stealer, password-stealer malware. The cycle feeds itself.
Another way attackers exploit WordPress is by hiding a backdoor in the lesser-known folder mu-plugins. Any plugins stored in this folder load automatically without showing in the dashboard. This gives attackers time to go undetected for a long time.
This kind of login data pattern is frequent in stolen files. As explained by Hudson Rock, password-stealing malware generates stealer logs containing username, password, and cookies. Threat actors trade these files on Telegram and other private forums.
The post does not say where the buyer wants to get logins. But the format points that way. One industry guide says this type of malware took 1.8 billion credentials in 2025. Bulk logins can sell for as little as ten dollars, according to Wikipedia. Buyers often test them first, which matches the checker step in this post.
The CIS Exception
A lot of Russian-language forums have since banned attacks on CIS countries, which are mostly old Soviet states. Researchers call it an unwritten rule. You can see it in the malware, too some malware even refuses to run on a computer set to Russian.
But things have shifted, so that rule seems to have weakened. After Russia invaded Ukraine, the forum XSS reportedly stopped counting Ukraine as part of the CIS. Even so, the buyer’s decision lines up with the old habit. Maybe they just want to stay out of trouble at home. Russian authorities often overlook crimes committed against foreigners.
Stolen Admin Logins Create a Much Bigger Threat
This post falls into a broader trend. In March 2026, Brinztech announced the existence of a listing that included full administrator privileges to a Dutch online shop. In April, researchers warned about a plugin vulnerability, CVE-2026-1492, that let someone without a password gain administrator access.
WordPress plugins have also been used to plant persistent access, with hackers recently placing a backdoor in more than 30 plugins and triggering an emergency security patch. Also, SOCRadar talked about a toolkit that collected over 2.1 million WordPress admin passwords from more than 600,000 websites. The most popular one was admin:admin, found at 10,548 websites.
What Site Owners Can Do
Most of the fixes are simple. Use a long, unique password for every admin account. Turn on two-step login. Delete admin accounts nobody uses. Update plugins as soon as fixes come out.
Check your user list for admins you do not recognize. Attackers often add hidden ones. If a computer catches malware, clean it, change every password, and log out all active sessions. Stolen session cookies can still work after a password change.
Ask your host or a security plugin to scan for odd files, too. A new admin account or strange code in your theme files can be the first sign of a break-in.
Buyers like this one create demand, and demand rewards the people who steal logins. A forum post is only talk. But the request shows how routine this trade has become. For site owners, the safest move is to assume someone is already looking for the weak login.