Borderless Migration — Hidden Malware Removal & Cleanup
A live immigration consultancy, silently compromised — a hidden admin account, stolen logins and malicious code on every visitor's screen. Found, removed and verified clean.
Hidden backdoor removed · verified clean
Immigration Law Services · Australia · Same-day cleanup · 2026
The problem
Borderless Migration — a busy Australian immigration consultancy — was silently compromised by a sophisticated, multi-component attack. A PHP backdoor was hiding inside the Code Snippets plugin's database table, disguised as "Analytics Configuration." It had created a secret administrator account — completely invisible inside the WordPress admin — and was transmitting login credentials to an attacker-controlled server. On top of that, heavily obfuscated JavaScript had been injected into the theme's footer, so every visitor was being exposed to a client-side attack. The only visible symptom was a fake popup; everything else stayed hidden.
What we did
- Ran a deep database scan of the full SQL export and found the active backdoor (GAnalytics family) hidden in the wp_snippets table.
- Identified the rogue administrator account (mail_daemon6fb98e18) the malware had created — confirmed full admin rights and that it was hidden from the admin panel.
- Decoded the malware's 18 attacker-controlled C2 domains and confirmed the live command server (waterpump41.world) the stolen credentials were being sent to.
- Found the obfuscated JavaScript injection in the active theme's footer.php through manual file review in cPanel.
- Removed every malware component via direct database queries and cPanel File Manager — bypassing the plugin interfaces the malware had hooked to hide itself.
- Removed the risky automatic-page-generator plugin and installed Wordfence for ongoing protection.
- Ran a full verification: 19MB database re-checked, 8,347 PHP files scanned against known backdoor signatures, and a live Wordfence scan of 15,624 files.
The result
The site is fully clean. Every malware component was removed and independently confirmed through three separate methods — a database re-scan, a file scan, and a live Wordfence analysis returning 0 issues across 15,624 files. The attacker's access was completely cut off. Wordfence is now active for ongoing protection, with a follow-up scan scheduled in 30 days to confirm there is no re-infection.
Want results like this?
Tell us what your website needs. We’ll handle the rest — no jargon, no hidden fees.
UK Registered Company · No contracts · Cancel anytime · Response within 4 hours