Cybersecurity researchers have uncovered a WordPress compromise featuring a backdoor, codenamed SC, that utilizes multiple persistence mechanisms. This design ensures the payload continuously reappears, even after administrators attempt to clean the infected site. The malware has been described as a "self-healing mesh" by Sucuri.
The SC backdoor maintains its presence through at least eight different locations, including various files, the WordPress database, and shared memory segments. This distributed approach means that if one part of the backdoor is removed, another can restore it, creating a resilient infection that is challenging to eradicate. The system lacks a single point of failure that can be targeted for removal.
The malware employs obfuscation techniques, including a decoder that uses a substitution cipher to unscramble its code. This makes analysis and detection more difficult for security professionals. The absence of readable function names further complicates efforts to understand and neutralize the threat.
The eight identified components include .user.ini for auto-prepending a loader, wp-content/c1b12371.php as a loader, and wp-content/.c1b12371.php as a first-stage loader. Other critical parts are wp-content/db.php and wp-content/advanced-cache.php, which carry and redeploy the payload from multiple sources. A theme-resident twin, wp-content/themes/khorshidi/functions.php, also exists, alongside the actual malware installed as a must-use plugin and normal plugin, wp-content/mu-plugins/hyper-engine-kit.php and wp-content/plugins/hyper-engine-.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity researchers have identified a sophisticated WordPress backdoor, codenamed SC, that employs multiple persistence mechanisms across files, the database, and shared memory to rebuild itself even after cleanup attempts. This malware creates a circular system where each component can restore others, making it difficult to remove completely.