SC WordPress Backdoor Rebuilds Itself After Cleanup

SC WordPress backdoor diagram showing self-healing loaders and a blockchain-controlled command channel, a hard case for WordPress malware cleanup

Deleting the Plugin Is Not Enough

Removing the malicious plugin does not solve the problem. A leftover copy simply rebuilds the infection.

The firm Sucuri analyzed the SC backdoor. It takes hold in WordPress across several layers at once. It returns within seconds after a routine cleanup. The overall spread of this malware family remains unknown.

A Mesh of Eight Components

SC stores its parts in at least eight components:

  • The .user.ini configuration file
  • Two loaders inside wp-content
  • The db.php and advanced-cache.php files
  • An injected block in the functions.php file of the active theme
  • Two identical copies of a fake plugin named Hyper Engine Kit

If one component vanishes, the others check for it. They then write it back.

The Hidden Payload

The main trouble hides outside the file system. A full compressed copy of the payload sits in the options table of the WordPress database. On servers with System V, another copy may also live in a shared memory segment.

Consequently, deleting every suspicious PHP file does not guarantee a clean site. The next request to the site can restore the whole chain.

Stealth Against Administrators

The backdoor works hard to stay out of sight. SC removes itself from the plugin list and from update checks. It creates a hidden account with full rights. It can also forge working login cookies for that account.

Similar hidden admin access has appeared in attacks through WordPress plugins before. SC, however, adds a separate self-healing circuit to it.

Blockchain-Based Command and Control

For its commands, the malware uses public Ethereum RPC gateways. In the sample, Sucuri counted about twenty such access points. Through them, the code reads instructions from a smart contract.

Blocking one address does not cut the link. The backdoor simply switches to other legitimate gateways and keeps receiving commands.

What SC Collects and Can Do

After launch, SC gathers the site address, the WordPress and plugin versions, and the active themes. It also collects administrator session tokens.

The reply from the control infrastructure may carry JavaScript to inject into pages. It may also carry new PHP code and a list of security plugins to disable or delete. On an online store, injected JavaScript could capture payment data.

Unknown Entry Point and Cleanup Advice

Sucuri did not determine the first way in for the analyzed case. In the WordPress ecosystem, attackers regularly exploit vulnerable plugins and themes. They also use weak passwords and supply chain attacks. In September, a separate flaw showed how a link opened by an administrator could end in a theme install and code execution.

For cleanup, Sucuri gives a clear order of steps:

  • First, stop the malicious code from running.
  • Next, remove copies from the database, shared memory, cron jobs, and database triggers.
  • Only then clean the files.
  • Afterward, rescan the site, close the original entry point, and rotate credentials.

If any component returns, one of the persistence mechanisms survived.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply