Cybersecurity experts have unveiled a sophisticated WordPress security threat where attackers use persistent tactics to ensure continual reinfection of the site. Dubbed ‘SC’, this backdoor utilizes multiple methods across files, databases, and shared memory to maintain its presence without needing repeated intrusions.
Mechanisms of Persistence
The malware, identified as SC due to the ‘SC_’ markers in its code, has been labeled a ‘self-healing mesh’ by Sucuri, utilizing blockchain technology for control. According to researcher Gabriel Barbosa, the payload is distributed across at least eight different components, which can regenerate each other if one is removed.
This system operates by replacing deleted plugins with drop-ins, which are then rewritten by themes or database entries. Even after thorough file cleaning, the system can reestablish itself from these alternate sources, creating a robust circular system without a single failure point.
Technical Details of the Backdoor
The backdoor employs a variety of tactics, including using unreadable function names and a substitution cipher-decoder. Critical components include ‘.user.ini’ for PHP auto-prepend, and several files in ‘wp-content’, such as ‘c1b12371.php’, ‘db.php’, and ‘advanced-cache.php’. These files work together to detect and reconstruct the backdoor from different sources.
Moreover, theme files like ‘functions.php’ and the plugin ‘hyper-engine-kit.php’ play crucial roles in maintaining the backdoor’s operations. The malware’s functions include concealing its presence, communicating through the Ethereum blockchain, and creating hidden administrator accounts.
Implications and Security Measures
This backdoor allows attackers to commandeer WordPress sites, inject malicious scripts, and potentially compromise visitors. The use of System V shared memory ensures persistence even after file deletions, making it particularly resilient on shared hosting environments.
While the initial infection vector remains unknown, common entry points include exploiting vulnerabilities in WordPress, plugins, and themes, or using weak credentials. The SC backdoor exemplifies the complexity of modern WordPress infections, which can distribute identical backdoor copies across various components and leverage legitimate infrastructures like blockchain for command channels.
Recent Exploitation Concerns
In related news, a critical SQL injection vulnerability in the wpForo Forum WordPress plugin (CVE-2026-1581) has been actively exploited. Affecting versions up to 2.4.14, this flaw has seen limited but notable exploitation attempts from multiple countries, underscoring ongoing threats to WordPress security.
Security professionals emphasize the importance of regular updates and strong security practices to mitigate such risks. The persistence of the SC backdoor and similar threats highlights the need for vigilance and comprehensive defense strategies in web security.
