This WordPress backdoor regrows from any surviving copy

Sucuri's SC backdoor hides in eight places and rebuilds itself from any one that survives cleanup.

CSBadmin
2 Min Read

Cleaning a hacked WordPress site usually means deleting the bad file. A newly documented backdoor makes that advice useless.

Sucuri named the backdoor SC, a nod to the SC_ markers it stamps into infected code. The firm describes it as a self-healing mesh, and it takes its orders through the Ethereum blockchain. Copies of the payload sit in at least eight spots at once, scattered across files, the database, and shared memory, and any one of them can regenerate the rest.

The result is a loop with no clean exit. Scrubbing the fake plugin only hands the job to a drop-in, and wiping that drop-in just hands it to the theme. Even a full disk cleanup buys no relief, because the next page view pulls the whole assembly back from either the database or a chunk of shared memory. That segment lives in RAM, so it outlasts file scrubs and database cleanups alike.

The pieces include a modified .user.ini, a hidden loader, a db.php drop-in carrying the payload in compressed form, an advanced-cache.php file, a theme functions.php twin, and the final malware planted as both a normal and a must-use plugin.

Once active, SC hides itself from the admin plugins screen, fetches extra payloads, creates a hidden administrator, and can inject JavaScript to skim visitors or run arbitrary PHP.

How it first got onto the sites is unknown. Sucuri points to the usual suspects: unpatched plugins, weak logins, and supply-chain hits on popular themes and add-ons.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.