Quick Takeaways
- A sophisticated WordPress backdoor named "SC" employs multiple persistent, self-healing components across files, database, and shared memory, making removal extremely difficult.
- The malware can hide from admin screens, inject malicious scripts targeting site visitors, control plugins, and establish command-and-control channels via the Ethereum blockchain.
- A high-severity, unauthenticated SQL injection vulnerability (CVE-2026-1581) in the wpForo plugin is actively exploited, risking unauthorized data access and site compromise.
The Threat, Techniques, and Targets
Cybersecurity experts have identified a sophisticated WordPress backdoor that rebuilds itself after cleanup. The malware is called SC, referring to “SC_” markers in the code. It acts as a “self-healing mesh” that is controlled via blockchain. The backdoor exists in at least eight different places, including files, the database, and shared memory. Each part can rebuild the others, making removal difficult.
The malware uses multiple techniques to maintain persistence. It plants files like “.user.ini” and “wp-content/c1b12371.php” that load the backdoor during PHP requests. It also uses scripts like “db.php” and “advanced-cache.php” to decode and deploy the payload from various sources such as ZIP files and database entries. Additionally, it injects code into theme functions and must-use plugins for redundancy.
The attack targets WordPress sites running various themes and plugins. The malware can hide from admin plugins and updates, making detection hard. Its communication with a command-and-control server is done through the Ethereum blockchain. The backdoor can fingerprint sites, fetch extra payloads, create hidden admin accounts, and run malicious scripts on visitors. This gives threat actors full control over infected sites.
Impact, Implications, and Remediation Guidance
This malware can severely compromise WordPress sites. It can allow attackers to insert malicious scripts that target site visitors with malware or skimmers. Because the backdoor can recreate itself regardless of cleanup efforts, removing it is complex. It also hides from normal security checks by using legitimate-looking files and encrypted code.
The infection’s use of shared memory, especially on servers that support System V, means it can survive file system deletion and database cleaning. This makes it resistant to typical cleanup methods. Furthermore, its ability to communicate using blockchain infrastructure complicates detection and takedown efforts.
For remediation, it is important to consult the website’s software vendor or a cybersecurity professional. They can provide specific guidance on thoroughly removing the backdoor and preventing future infections. Because this threat is highly resilient, professional help is recommended to ensure the site is fully secured.
Discover More Technology Insights
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
