WordPress backdoor ‘SC’ employs self-repairing mechanisms to evade detection

Published:

Cybersecurity researchers have identified a sophisticated WordPress backdoor, codenamed SC, which employs multiple persistence mechanisms to ensure its payload can regenerate itself after attempts to remove it. This malware, described by Sucuri as a “self-healing mesh,” utilizes a decentralized approach, leveraging blockchain technology to maintain its presence on compromised sites.

According to Sucuri, the SC backdoor operates by distributing its components across various locations, including files, the database, and shared memory. Security researcher Gabriel Barbosa noted that the malware can rebuild itself from at least eight different locations, making it exceptionally resilient to cleanup efforts. “Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it,” Barbosa explained, highlighting the circular nature of the system that complicates removal.

Mechanics of the SC Backdoor

The SC backdoor is designed to evade detection and removal through a series of interconnected components. These include:

  • .user.ini: Configures the server to run a loader before every PHP request.
  • wp-content/c1b12371.php: Acts as the primary loader, including hidden files if present.
  • wp-content/.c1b12371.php: The first-stage loader that can recreate a fake plugin from multiple sources.
  • wp-content/db.php: Contains the entire backdoor payload in a compressed format, redeploying it as needed.
  • wp-content/advanced-cache.php: Rebuilds the plugin from various sources, including shared memory and the database.
  • wp-content/themes/khorshidi/functions.php: A theme-based version of the backdoor that ensures the plugin’s presence.
  • wp-content/mu-plugins/hyper-engine-kit.php: The main malware component installed as both a must-use and normal plugin.
  • wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php: A redundant copy of the backdoor payload.

The backdoor’s capabilities extend beyond mere persistence; it can hide from the admin interface, communicate with a command-and-control (C2) server via the Ethereum blockchain, and execute arbitrary PHP code. This allows attackers to take control of the WordPress site, inject malicious JavaScript, and create hidden administrator accounts.

Delivery and Exploitation Vectors

While the exact delivery method for the SC backdoor remains unclear, common initial access vectors include exploiting known vulnerabilities in WordPress, plugins, and themes, as well as weak login credentials. Additionally, software supply chain attacks targeting popular plugins and insecure media upload features are potential entry points for attackers.

As Sucuri pointed out, the SC backdoor exemplifies a modern approach to WordPress infections, where the malware operates as a system rather than a single file. This complexity makes it challenging for site administrators to effectively remove the threat.

Related Vulnerability: wpForo Forum Plugin

The emergence of the SC backdoor coincides with the active exploitation of a high-severity SQL injection vulnerability in the wpForo Forum WordPress plugin, identified as CVE-2026-1581 (CVSS score: 7.5). This vulnerability affects all versions of the plugin up to 2.4.14 and has been linked to fewer than 20 exploitation attempts since July 2026, originating from various locations including Bulgaria, Switzerland, and Yemen.

As the cybersecurity landscape continues to evolve, the SC backdoor serves as a stark reminder of the need for robust security measures and vigilant monitoring of WordPress installations to mitigate the risks posed by such advanced threats.

For further details, refer to The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NIST publishes guidelines for secure remote access in water and wastewater operational technology environments

Recent cyberattacks targeting the U.S. water and wastewater systems (WWS) sector have underscored the urgent need for enhanced cybersecurity measures within critical infrastructure. The...

Red Hat releases important security update for pcp in RHEL 8.8

Red Hat has announced an important security update for the Performance Co-Pilot (pcp) in Red Hat Enterprise Linux (RHEL) 8.8, specifically targeting Update Services...

OpenAI disrupts alleged distillation attack by Chinese rival Moonshot AI

OpenAI has reported the disruption of a "coordinated campaign" aimed at extracting reasoning capabilities from its AI models, attributing the activity to a Chinese...

Microsoft Ignite 2026 to focus on AI-driven security solutions and strategies

Microsoft Ignite 2026 is set to emphasize AI-driven security solutions, reflecting the growing integration of artificial intelligence in cybersecurity practices. Scheduled for November 17-20,...