Image: thaicert.or.th · rights & removal
SC Malware Found on WordPress, Embedding Itself Across Multiple Locations and Rebuilding Backdoors After Removal
Reporting by Thailand ThaiCERT AdvisoriesRead the original at thaicert.or.th
Executive Summary
Facts Only
* Researchers from Sucuri disclosed the discovery of SC malware on WordPress websites.
* The malware uses multiple persistence mechanisms to restore deleted backdoor components after administrator removal of files.
* At least eight malware components were identified across WordPress files, the database, and shared memory.
* Malware embeds itself in locations such as .user.ini, db.php, advanced-cache.php, theme functions.php files, regular plugins, and Must-Use plugins.
* Payloads are stored in the database and shared memory.
* Removing one component does not eliminate the ability for remaining components to rewrite deleted content.
* The backdoor can hide from plugin management interfaces, create hidden administrator accounts, execute PHP code, download payloads, and inject JavaScript.
* Communication with command-and-control (C2) systems uses Ethereum infrastructure and smart contracts.
Full Take
From the original · Thailand ThaiCERT Advisories
543/69 Friday, October 2, 2026 Researchers from Sucuri have disclosed the discovery of malware on WordPress websites known as SC, which uses multiple persistence mechanisms to restore deleted backdoor components even after administrators remove detected files.Read the full story at thaicert.or.th
Sentinel — Human
The text reads like a factual report or technical advisory, exhibiting typical journalistic structure and direct instruction, with low indicators of synthetic generation.
