Oh.. how funny..
Orig attacker runs installer, takes control of the site. Leaves, hasn't been back.
New attacker uses WPJSON to identify the user (the other attacker) starts to brute force the username using XMLRPC.
Oh man.. who is going to win..
#security #wordpress