
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.
The backdoor has been codenamed SC after the “SC_” markers present in the injected content. Sucuri has described the malware as a “self-healing mesh” that’s blockchain-controlled.
“The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others,” security researcher Gabriel Barbosa said.
“Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it.”
According to Sucuri, the malware does not have any readable function names, instead employing a decoder to unscramble the code using a substitution cipher. A summary of the eight components is as follows –
Regardless of the method used to launch the backdoor, it carries out a number of actions, including hiding itself from the admin plugins screen or in update checks, communicating with a command-and-control (C2) server using the Ethereum blockchain, fingerprinting the infected site and retrieving additional payloads, creating a hidden administrator account, and running the reinfection loop.
The backdoor’s capabilities allow the operator to take control of the WordPress site, fetch arbitrary JavaScript to inject and target site visitors with skimmers (or other malware), run PHP code, and deactivate or delete specific plugins.
“On servers that support System V shared memory, the payload is written into a segment identified by a fixed numeric key,” Sucuri said. “That segment lives in RAM, so it survives file deletion and database cleanup alike, and on shared hosting it can even be owned by a different account.”
“The infection registers cron hooks, including randomized names alongside a known fetch hook. System cron runs the WordPress cron file, not visitor traffic, then triggers redeployment on schedule.”
It’s currently not known how the malware is delivered to the WordPress site. However, typical initial access vectors include known security flaws in WordPress, plugins, and themes; weak login credentials; software supply chain attacks targeting popular plugins; and the exploitation of insecure media or form upload features to push PHP web shells into server directories.
“SC is a reminder that a modern WordPress infection can be a system rather than a file,” Sucuri said. “This toolkit spreads identical copies of one backdoor across drop-ins, the theme, a fake plugin in two locations, the database, and shared memory, hides its command channel inside legitimate blockchain infrastructure, and rewrites itself from any surviving copy on the very next request.”
The disclosure comes as a high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin (CVE-2026-1581, CVSS score: 7.5) has come under active exploitation. The issue affects all versions of the plugin up to, and including, 2.4.14.
According to telemetry data from Previdian, fewer than 20 exploitation attempts targeting the vulnerability have been observed since July 3, 2026. The activity has originated from five unique attacker IP addresses located in Bulgaria, Switzerland, France, the U.S., and Yemen.
#after #and #backdoor #cleanup #database #files #itself #memory. #news #rebuilds #shared #using #wordpress — News
© Bulletproof Servers. All rights reserved.