
WordPress Backdoor Rebuilds Itself After Every Cleanup Attempt
A new WordPress backdoor uses multiple persistence methods to survive cleanup, hiding in eight locations and communicating via blockchain.
Cybersecurity researchers at Sucuri have uncovered a sophisticated WordPress backdoor that can rebuild itself after any cleanup attempt. Codenamed SC because of the "SC_" markers in its code, the malware spreads identical copies across at least eight separate places on a server: files, the database, and even shared system memory, and each of those places can repair all the others if any are removed.
The discovery, detailed by researcher Gabriel Barbosa, shows a "self-healing mesh" that makes the infection nearly impossible to eradicate without a coordinated cleanup of every hiding spot at once. "Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment," Barbosa said. The result is a circular system with no single point that can be removed to stop it.
The eight persistence components start with a .user.ini file that forces the server to run a loader before every PHP request. That loader, a hidden dot-prefixed file, then locates a fake plugin and rebuilds it in the must-use plugins directory from three sources: an existing plugin copy, a cached stub, and a ZIP bundle. Other drop-ins like wp-content/db.php and wp-content/advanced-cache.php contain compressed, Base64-encoded copies of the whole payload. When any part is missing or too small, they decode and re-deploy the malware. Even the site's theme folder contains a duplicate inside its functions.php file that rewrites the backdoor every time the theme is loaded. Additionally, the malware installs itself as both a must-use plugin and a normal plugin under two different names for redundancy.
Once active, the backdoor hides itself from the WordPress admin plugins list and lies about its presence during update checks. It connects to a command-and-control server using the Ethereum blockchain, making the traffic blend in with legitimate blockchain activity. The attack operator can then fingerprint the infected site, create a hidden administrator account, fetch JavaScript payloads to inject into the site and deliver skimmers or other malware to visitors, execute arbitrary PHP code, and disable or delete other plugins. On servers that support System V shared memory, the payload is written into RAM with a fixed numeric key, so it survives file deletion and some database cleanups. It can even be owned by a different hosting account on shared servers, making it hard to track. The infection also sets up scheduled cron tasks that trigger redeployment on a regular schedule, independent of site visitors.
It is not yet known how attackers initially deliver the SC backdoor onto WordPress sites. Common access routes include exploiting known flaws in WordPress core, plugins, or themes, using weak login credentials, attacking software supply chains to compromise popular plugins, or uploading PHP shells through insecure media or form upload functions. The complexity of the persistence system means that once a site is infected, a simple file removal or plugin deletion will not stop the backdoor; a thorough, multi-location cleanup is necessary.
For website owners, the SC backdoor highlights the need for strong, proactive security measures. Managed WordPress hosting like AEU Hosting includes automated malware scanning and expert support that can detect and handle such persistent infections before they spread, removing the burden of manual cleanup from site owners. Regular updates, strong passwords with two-factor authentication, and security monitoring remain essential.
In a separate but related development, a high-severity SQL injection vulnerability in the wpForo Forum WordPress plugin (tracked as CVE-2026-1581, with a CVSS score of 7.5) has been actively exploited since July 2026. The flaw affects all versions up to 2.4.14 and allows unauthenticated attackers to inject malicious SQL queries. According to telemetry from Previdian, fewer than 20 exploitation attempts have been recorded so far, originating from five IP addresses in Bulgaria, Switzerland, France, the United States, and Yemen. Website owners using the wpForo Forum plugin should update immediately to the latest patched version to prevent compromise.
So schützen Sie sich
- Keep your WordPress core, plugins, and themes updated at all times, and enable automatic updates for minor releases.
- Use strong, unique passwords and enable two-factor authentication for every administrator account on your website.
- Install a reputable security plugin that can scan for known malware and alert you to suspicious file changes.
- Back up your website regularly and store the backups off-site so you can restore a clean version if an infection is found.
- If you suspect a persistent infection, contact your hosting provider or a security professional for a thorough cleanup that checks all file locations, the database, and temporary memory.
Schwachstellen & Lösungen
- CVE-2026-1581 A high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin, affecting versions up to 2.4.14; update to the patched release to mitigate. Lösung & Details ansehen →
Begriffe Erklärt
- backdoor A hidden way into a computer system that allows an attacker to bypass normal login and security controls.
- must-use plugin A WordPress plugin that is automatically activated and cannot be disabled from the normal plugins screen; it loads before regular plugins.
- shared memory A temporary storage area in the computer's RAM that different programs can read and write to, allowing data to survive even after files on disk are deleted.
- blockchain A public digital ledger where transactions are recorded in blocks and linked together, often used for cryptocurrencies; in this attack, it is used to hide command traffic.
- command-and-control (C2) A server or communication channel that attackers use to send instructions to malware already installed on victim computers.
- SQL injection A type of attack where an attacker inserts malicious code into a website's database query, often to steal or modify data.