WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
swapupdate.in Oct 2, 2026

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

AI-summarised brief · reviewed before publication

Cybersecurity researchers uncovered a sophisticated WordPress backdoor, dubbed “SC,” that self‑rebuilds across files, the database, and shared memory. The malware deploys eight interlinked components—including user.ini, hidden loaders, and a must‑use plugin—each capable of recreating the others. Even after deleting or cleaning files, the backdoor restores itself from alternate sources such as a ZIP bundle, database, or System V shared‑memory segment, creating a circular persistence loop. The payload hides from admin screens, communicates via an Ethereum‑based C2 server, and fingerprints infected sites.

💡 Why It Matters

  • · The attack demonstrates a new level of resilience in web malware, forcing defenders to address multiple, redundant persistence vectors rather than a single removal point.