WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Security researchers have uncovered a sophisticated WordPress backdoor called “SC” that persistently rebuilds itself after cleanup by spreading its payload across files, the database, and shared memory. This self-healing malware uses multiple redundant loaders, including coded plugins and theme files, and communicates with a command-and-control server via the Ethereum blockchain to maintain control, evade removal, create hidden admin accounts, and deploy further malicious code. The complexity and multi-layered persistence mechanisms make it extremely difficult to fully eradicate from an infected WordPress site.

https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top