← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

WordPress Backdoor Uses Multiple Persistence Mechanisms to Self-Rebuild After Cleanup

🔄 Updated 21h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • The SC backdoor uses eight components for persistence.
  • Components are spread across files, database, and shared memory.
  • Each component can rebuild all other parts of the backdoor.
  • The malware uses a decoder and substitution cipher to obscure its code.

Sophisticated WordPress Backdoor Discovered

Cybersecurity researchers have uncovered a WordPress compromise featuring a backdoor, codenamed SC, that utilizes multiple persistence mechanisms. This design ensures the payload continuously reappears, even after administrators attempt to clean the infected site. The malware has been described as a "self-healing mesh" by Sucuri.

Multi-Point Persistence Strategy

The SC backdoor maintains its presence through at least eight different locations, including various files, the WordPress database, and shared memory segments. This distributed approach means that if one part of the backdoor is removed, another can restore it, creating a resilient infection that is challenging to eradicate. The system lacks a single point of failure that can be targeted for removal.

Obfuscation Techniques Employed

The malware employs obfuscation techniques, including a decoder that uses a substitution cipher to unscramble its code. This makes analysis and detection more difficult for security professionals. The absence of readable function names further complicates efforts to understand and neutralize the threat.

Key Components of the Backdoor

The eight identified components include .user.ini for auto-prepending a loader, wp-content/c1b12371.php as a loader, and wp-content/.c1b12371.php as a first-stage loader. Other critical parts are wp-content/db.php and wp-content/advanced-cache.php, which carry and redeploy the payload from multiple sources. A theme-resident twin, wp-content/themes/khorshidi/functions.php, also exists, alongside the actual malware installed as a must-use plugin and normal plugin, wp-content/mu-plugins/hyper-engine-kit.php and wp-content/plugins/hyper-engine-.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have identified a sophisticated WordPress backdoor, codenamed SC, that employs multiple persistence mechanisms across files, the database, and shared memory to rebuild itself even after cleanup attempts. This malware creates a circular system where each component can restore others, making it difficult to remove completely.