Skip to content

Image: thaicert.or.th · rights & removal

Executive Summary

Researchers from Sucuri discovered malware on WordPress websites designated as SC, which employs multiple persistence mechanisms to restore deleted backdoor components following administrator file removal. At least eight malware components were identified across WordPress files, the database, and shared memory, each capable of facilitating the restoration of other removed components. The malware embeds itself in numerous locations including .user.ini, db.php, advanced-cache.php, theme functions.php files, regular plugins, and Must-Use plugins. Payload copies are stored in the database and shared memory. The malware hides itself from plugin management interfaces, creates hidden administrator accounts, executes PHP code, downloads additional payloads, injects JavaScript, and utilizes Ethereum infrastructure and smart contracts for command-and-control communication.

Facts Only

* Researchers from Sucuri disclosed the discovery of SC malware on WordPress websites.
* The malware uses multiple persistence mechanisms to restore deleted backdoor components after administrator removal of files.
* At least eight malware components were identified across WordPress files, the database, and shared memory.
* Malware embeds itself in locations such as .user.ini, db.php, advanced-cache.php, theme functions.php files, regular plugins, and Must-Use plugins.
* Payloads are stored in the database and shared memory.
* Removing one component does not eliminate the ability for remaining components to rewrite deleted content.
* The backdoor can hide from plugin management interfaces, create hidden administrator accounts, execute PHP code, download payloads, and inject JavaScript.
* Communication with command-and-control (C2) systems uses Ethereum infrastructure and smart contracts.

Full Take

The existence of malware capable of self-restoration across diverse layers—filesystem, database, memory, and plugin structures—suggests a systemic challenge to traditional remediation efforts where simple file or plugin removal is insufficient. The mechanism relies on distributed persistence, meaning attackers intentionally seed multiple locations, creating redundancy that resists standard cleanup protocols. This shifts the security paradigm from reactive clean-up to proactive systemic identification of all potential persistence vectors. The use of advanced techniques like embedding within shared memory and leveraging blockchain infrastructure for C2 communication indicates an evolution in attacker sophistication, moving beyond simple file-based threats toward integrated, resilient control systems. The instruction for administrators to sweep for database entries, cron hooks, triggers, and hidden accounts underscores that the vulnerability is not just in code execution but in the operational integrity of the entire system architecture. This implies a pattern where persistence is designed to outmaneuver detection; therefore, security strategies must focus on immutable state verification rather than singular point remediation. What structural assumptions about WordPress's integrity are being challenged by this level of multi-layered persistence? How does the necessity of checking esoteric locations like .user.ini and shared memory alter the definition of a successful security audit?

From the original · Thailand ThaiCERT Advisories

543/69 Friday, October 2, 2026 Researchers from Sucuri have disclosed the discovery of malware on WordPress websites known as SC, which uses multiple persistence mechanisms to restore deleted backdoor components even after administrators remove detected files.
Read the full story at thaicert.or.th

Sentinel — Human

Confidence

The text reads like a factual report or technical advisory, exhibiting typical journalistic structure and direct instruction, with low indicators of synthetic generation.

Signals Detected
low severity: Moderate sentence length variance; shifts between descriptive and instructional tone.
low severity: Clear, direct presentation of technical findings followed by prescriptive advice. Exhibits a clear focus.
low severity: Structured flow from discovery to persistence mechanisms to remediation steps; logically connected without overt template repetition.
low severity: Specific technical details (file names, methods) appear plausible and directly tied to the stated research context.
Human Indicators
The text contains specific, actionable security advice targeting WordPress administrators (e.g., 'should not remove only the identified files...'), suggesting a practical, human-authored intent beyond pure informational dumping.
SC Malware Found on WordPress, Embedding Itself Across Multiple Locations and Rebuilding Backdoors After Removal | Huntaegis