WeTransfer A.I CyberSecurity Scoring
WeTransfer
Company Information
Website:https://wetransfer.com/explore/advertising
Employees number:86
Number of followers:44,416
NAICS:5112
Industry Type:Software Development
Homepage:wetransfer.com
WeTransfer Risk Score (AI oriented)
Between 700 and 749
WeTransferSoftware Development
Updated:
15/06/2026
15/06/2026
737/1000
Moderate
Ba
WeTransfer Global Score (TPRM)
xxxx
WeTransferSoftware Development
Score locked

WeTransferModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
738
JULY 2026
738
JUNE 2026
737
MAY 2026
737
APRIL 2026
737
MARCH 2026
736
FEBRUARY 2026
736
JANUARY 2026
735
DECEMBER 2025
752
Cyber Attack
01 Dec 2025 • WeTransfer
WeTransfer: Threat Actor Malware Platform Exposed by Unsecured PHP Install Page
Malware Distribution Platform Exposed Due to Critical Security Misconfiguration
734
CRITICAL-18
WET1781512078
Malware Distribution Platform Exposed Due to Critical Security Misconfiguration
A cybersecurity researcher recently uncovered a live malware distribution platform after discovering an exposed PHP installation page a basic operational security failure that granted full administrative access to the threat actor’s backend infrastructure.
The investigation began when a researcher on X (formerly Twitter) identified a suspicious domain linked to a fake software download portal, a common tactic in SEO poisoning campaigns designed to manipulate search rankings and redirect victims to malware-laden downloads. Using the directory-bruteforcing tool ffuf, the researcher identified sensitive endpoints, including `/admin/login.php` and `/config/database.php`.
The most critical oversight was the presence of a live `/install/install.php` page on a production server a textbook security misconfiguration where deployment steps are left incomplete. The researcher tested the application’s reinstallation safeguards and found none. By spinning up a Docker-hosted MySQL instance via ngrok and submitting controlled database credentials, they bypassed the setup process entirely, creating a new administrator account and redirecting the application’s database to their own infrastructure.
After a brief 500 Internal Server Error likely caused by the database conflict the threat actor restored the application, but the researcher’s session remained active. Since the PHP application stored session state server-side rather than in the database, the backend reconfiguration did not invalidate existing sessions. This allowed full access to the administrative dashboard, which displayed panels in Russian for managing keywords, visitor tracking, downloads, and payload configurations key components of an SEO-driven malware distribution operation.
The backend, built on a PHP/MySQL stack, dynamically generated download pages based on URL parameters. Victims were funneled through intermediate redirectors, including Google Colab pages, before reaching the final payload a compressed archive containing malware. This layered redirect chain is a known tactic to obscure the true hosting infrastructure from users and security scanners.
The incident aligns with a broader trend of threat actor OPSEC failures, including cases documented by Vectra AI in December 2025, where groups like Devman ransomware and North Korea’s Lazarus Group exposed internal infrastructure due to rushed deployments and inadequate hardening.
Indicators of Compromise (IOCs):
- Domains: `micronsoftwares[.]com`, `wetransfer[.]icu`
- SHA256: `7b03fb383a5ce784a3cb9b0f8a76a84e984d14e553de5d98faff3d07d9793085` (payload.exe)
The threat actor patched the initialization flaw shortly after the breach, but the brief exposure provided rare insight into the mechanics of an active malware distribution operation. At the time of reporting, the domains remained active.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WeTransfer ??
What was WeTransfer's A.I Rankiteo Cyber Score in July 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in June 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in May 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in April 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in March 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in February 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in January 2026 ??
What was WeTransfer's A.I Rankiteo Cyber Score in December 2025 ??
What was WeTransfer's A.I Rankiteo Cyber Score in November 2025 ??
What was WeTransfer's A.I Rankiteo Cyber Score in October 2025 ??
What was WeTransfer's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on WeTransfer's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WeTransfer ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WeTransfer's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?