SC Malware Found on WordPress, Embedding Itself Across Multiple Locations and Rebuilding Backdoors After Removal

Views: 511 views

543/69 Friday, October 2, 2026

Researchers from Sucuri have disclosed the discovery of malware on WordPress websites known as SC, which uses multiple persistence mechanisms to restore deleted backdoor components even after administrators remove detected files. Researchers identified at least eight malware components distributed across WordPress files, the database, and shared memory, with each component capable of helping restore others that have been removed. At this time, researchers have not been able to determine how the attackers initially gained access to the affected websites.

The malware embeds itself in multiple locations, including .user.ini, db.php, advanced-cache.php, theme functions.php files, regular plugins, and Must-Use plugins. It also stores copies of its payload in the database and shared memory. If one component is removed, the remaining components can rewrite the deleted content back into the system. The backdoor can also hide itself from the plugin management interface, create hidden administrator accounts, execute PHP code, download additional payloads, and inject JavaScript into websites. It also uses Ethereum infrastructure and smart contracts as part of its mechanism for communicating with command-and-control (C2) systems.

WordPress administrators who detect this type of infection should not remove only the identified files or plugins. They should thoroughly identify and eliminate all persistence mechanisms, including malicious database entries, shared memory data, cron hooks, database triggers, unknown administrator accounts, and modified files within wp-content. Administrators should also inspect .user.ini or .htaccess files for suspicious auto_prepend_file directives. After removing the malware, they should investigate the initial access vector, update WordPress core, themes, and related plugins, and rotate any credentials that may have been exposed to prevent attackers from regaining access to the website.

Source: https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html