The SC WordPress malware family maintains a self-healing backdoor mesh that can restore deleted components within seconds. It distributes redundant payloads among WordPress core and theme files, early-loading PHP configuration, fake duplicate plugins and drop-ins, database records, scheduled tasks, recovery archives, and System V shared memory. Remaining components can recreate removed ones, while hidden privileged administrator accounts, forged authentication cookies, and stolen administrator-session tokens preserve attacker access. The initial access vector and number of affected sites remain unknown.
SC retrieves command-and-control instructions through public Ethereum RPC gateways and smart-contract method selectors, enabling operators to rotate infrastructure and deliver replacement PHP payloads, browser-side JavaScript, or commands to remove security plugins. The malware can collect site reconnaissance data, disable defenses, and inject payment-skimming JavaScript into online stores. Defenders should first prevent malicious code execution, then coordinate removal of filesystem artifacts, database payloads and triggers, shared-memory content, cron jobs, hidden accounts, and recovery mechanisms; organizations should also rotate credentials and remediate the original intrusion path.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Sucuri analysts identified the SC malware during website-cleanup work and documented its layered persistence, which can restore removed components from files, databases, scheduled tasks, and System V shared memory. The initial compromise vector and number of affected sites were not established.
Sucuri published an analysis of the SC WordPress backdoor family, detailing its redundant loaders and payload stores, Ethereum RPC-based command-and-control mechanism, administrator-account concealment, and recommended coordinated remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.sucuri.net
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.