Security researchers identified a phishing campaign targeting GoDaddy’s ManageWP service. Attackers use malicious Google Ads to direct users to fake login pages. These pages steal credentials and two-factor authentication codes. Attackers send stolen data to controlled Telegram accounts.

ManageWP supports over one million websites. The campaign utilizes a private phishing framework of Russian origin. The report confirms at least 200 victims.