WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
AI-summarised brief · reviewed before publication
Cybersecurity researchers uncovered a sophisticated WordPress backdoor, dubbed “SC,” that self‑rebuilds across files, the database, and shared memory. The malware deploys eight interlinked components—including user.ini, hidden loaders, and a must‑use plugin—each capable of recreating the others. Even after deleting or cleaning files, the backdoor restores itself from alternate sources such as a ZIP bundle, database, or System V shared‑memory segment, creating a circular persistence loop. The payload hides from admin screens, communicates via an Ethereum‑based C2 server, and fingerprints infected sites.
💡 Why It Matters
- · The attack demonstrates a new level of resilience in web malware, forcing defenders to address multiple, redundant persistence vectors rather than a single removal point.