Sucuri researchers have documented a WordPress backdoor designed to rebuild itself when defenders remove only part of the infection. The company calls the malware SC and describes a mesh of cooperating components distributed across the site’s files, database and operating environment.
Persistence extends beyond a single malicious file
Sucuri said copies or recovery logic can reside in WordPress files, database options, archives, scheduled tasks and System V shared memory. A surviving component can restore removed pieces during a later request. The command mechanism also uses blockchain infrastructure, reducing its dependence on a conventional command domain that defenders could block or seize.
Cleanup requires a full-system investigation
Deleting one suspicious loader is unlikely to be sufficient. Responders should preserve evidence, enumerate web files and database options, inspect scheduled jobs and drop-ins, review memory-related artifacts where the platform permits it, and compare the installation with a trusted baseline. Credentials for WordPress, hosting, databases and deployment systems may also require rotation. Sites should be rebuilt from known-good components when integrity cannot be established. Further application-security reporting is available in the SectechMedia Technology News archive.

Leave a Reply