Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Backdoor Resists Removal with Reinfection Methods

WordPress Backdoor Resists Removal with Reinfection Methods

Posted on October 1, 2026 By CWS

Cybersecurity experts have unveiled a sophisticated WordPress security threat where attackers use persistent tactics to ensure continual reinfection of the site. Dubbed ‘SC’, this backdoor utilizes multiple methods across files, databases, and shared memory to maintain its presence without needing repeated intrusions.

Mechanisms of Persistence

The malware, identified as SC due to the ‘SC_’ markers in its code, has been labeled a ‘self-healing mesh’ by Sucuri, utilizing blockchain technology for control. According to researcher Gabriel Barbosa, the payload is distributed across at least eight different components, which can regenerate each other if one is removed.

This system operates by replacing deleted plugins with drop-ins, which are then rewritten by themes or database entries. Even after thorough file cleaning, the system can reestablish itself from these alternate sources, creating a robust circular system without a single failure point.

Technical Details of the Backdoor

The backdoor employs a variety of tactics, including using unreadable function names and a substitution cipher-decoder. Critical components include ‘.user.ini’ for PHP auto-prepend, and several files in ‘wp-content’, such as ‘c1b12371.php’, ‘db.php’, and ‘advanced-cache.php’. These files work together to detect and reconstruct the backdoor from different sources.

Moreover, theme files like ‘functions.php’ and the plugin ‘hyper-engine-kit.php’ play crucial roles in maintaining the backdoor’s operations. The malware’s functions include concealing its presence, communicating through the Ethereum blockchain, and creating hidden administrator accounts.

Implications and Security Measures

This backdoor allows attackers to commandeer WordPress sites, inject malicious scripts, and potentially compromise visitors. The use of System V shared memory ensures persistence even after file deletions, making it particularly resilient on shared hosting environments.

While the initial infection vector remains unknown, common entry points include exploiting vulnerabilities in WordPress, plugins, and themes, or using weak credentials. The SC backdoor exemplifies the complexity of modern WordPress infections, which can distribute identical backdoor copies across various components and leverage legitimate infrastructures like blockchain for command channels.

Recent Exploitation Concerns

In related news, a critical SQL injection vulnerability in the wpForo Forum WordPress plugin (CVE-2026-1581) has been actively exploited. Affecting versions up to 2.4.14, this flaw has seen limited but notable exploitation attempts from multiple countries, underscoring ongoing threats to WordPress security.

Security professionals emphasize the importance of regular updates and strong security practices to mitigate such risks. The persistence of the SC backdoor and similar threats highlights the need for vigilance and comprehensive defense strategies in web security.

The Hacker News Tags:backdoor malware, Blockchain, blockchain technology, Cybersecurity, database security, malware persistence, malware reinfection, PHP vulnerabilities, plugin vulnerabilities, shared memory, theme security, web security, website protection, WordPress plugins, WordPress security

Post navigation

Previous Post: WordPress Malware Resurfaces with Self-Healing Backdoor
Next Post: Businesses Unprepared for AI and Quantum Security Risks

Related Posts

Critical ServiceNow Vulnerabilities Demand Urgent Attention Critical ServiceNow Vulnerabilities Demand Urgent Attention The Hacker News
PaperCut Issues New Security Updates for Critical Flaws PaperCut Issues New Security Updates for Critical Flaws The Hacker News
CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428 CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428 The Hacker News
Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep The Hacker News
Phishing Campaigns Use MSP360 for Hidden Access Phishing Campaigns Use MSP360 for Hidden Access The Hacker News
Essential Steps CISOs Must Take for SOC Efficiency Essential Steps CISOs Must Take for SOC Efficiency The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark