Sucuri Finds Self-Rebuilding WordPress Backdoor Across Files, Database and Memory

WordPress application security and persistent malware analysis

Sucuri researchers have documented a WordPress backdoor designed to rebuild itself when defenders remove only part of the infection. The company calls the malware SC and describes a mesh of cooperating components distributed across the site’s files, database and operating environment.

Persistence extends beyond a single malicious file

Sucuri said copies or recovery logic can reside in WordPress files, database options, archives, scheduled tasks and System V shared memory. A surviving component can restore removed pieces during a later request. The command mechanism also uses blockchain infrastructure, reducing its dependence on a conventional command domain that defenders could block or seize.

Cleanup requires a full-system investigation

Deleting one suspicious loader is unlikely to be sufficient. Responders should preserve evidence, enumerate web files and database options, inspect scheduled jobs and drop-ins, review memory-related artifacts where the platform permits it, and compare the installation with a trusted baseline. Credentials for WordPress, hosting, databases and deployment systems may also require rotation. Sites should be rebuilt from known-good components when integrity cannot be established. Further application-security reporting is available in the SectechMedia Technology News archive.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *