A persistent threat is re-emerging on WordPress sites, utilizing a self-healing backdoor to reinstate malware almost instantly after removal. Known as SC, this backdoor infects through website files, databases, and server memory, ensuring its components can restore any that are removed.
How the SC Backdoor Operates
Investigations have yet to pinpoint the initial entry point or the scale of affected sites. However, once SC is installed, it exploits early loading features, themes, and plugins to sustain its presence. This underscores why merely checking the WordPress dashboard is insufficient to detect such infections.
Sucuri’s analysts uncovered SC during recent website cleanups, documenting their observations on September 30, 2026. According to their report shared with Cyber Security News, the backdoor embeds itself in at least eight locations and can reconstruct itself after visible files are eliminated.
Impact on WordPress Sites
Beyond repeatedly spawning malicious files, the backdoor can conceal administrator accounts, gather session tokens, and remove security plugins. It can also deploy browser scripts that might facilitate fraudulent transactions. While the report outlines these capabilities, it does not specify confirmed financial impacts.
SC’s resilience is attributed to its network of components that aid each other’s recovery. A configuration directive initiates a loader before standard PHP requests, even those not reaching WordPress. A visible intermediary loads concealed code, stabilizing the entry method while masking the main loader.
Strategies for Cleanup and Prevention
To effectively counter this threat, Sucuri advises halting execution before component removal. Replace the configuration’s loader target with inert content and remove the directive. As PHP can cache this setting for up to 300 seconds, immediate deletion might disrupt every PHP request on the account.
Next, clear database payloads, control settings, and shared memory copies. Remove malicious scheduled tasks and inspect database triggers before deleting hidden administrators. Unlike self-restoring malware, SC employs multiple independent recovery strategies.
Preventive Measures to Consider
Comprehensive prevention involves timely updates, utilizing a web application firewall, and regular reviews of database settings, scheduled tasks, triggers, and user accounts. Any returning file should indicate incomplete cleanup, warranting further investigation rather than repeated deletion.
Indicators of compromise include configuration files like .user.ini and php.ini, malicious file paths, and network behaviors involving public Ethereum gateways. Addressing the full set of observed gateways is essential to thwart SC’s operations.
In conclusion, while SC represents a sophisticated threat to WordPress sites, understanding its mechanisms and employing strategic cleanup and prevention measures can significantly mitigate its impact.
