
WordPress SC backdoor deploys eight redundant loaders across files, database, and System V shared memory
SC backdoor uses circular redundancy across eight storage methods including System V RAM segments to survive cleanup. Analysis reveals cross-account persistence risk on shared hosting and blockchain C2. Standard file deletion fails; full isolation and memory clearing required.
Sucuri researchers documented a WordPress infection where threat actors installed a self-replicating backdoor labeled SC. The payload uses a substitution cipher decoder and spreads across drop-ins, cache files, database entries, and RAM-based shared memory. Any single component can restore the full set on the next page load or cron run. Initial access vectors remain unidentified but align with common patterns of plugin vulnerabilities and weak credentials. Evidence from the Sucuri analysis shows explicit hooks into WordPress bootstrap points: auto_prepend_file directives, must-use plugin registration, and advanced-cache.php loading. The backdoor also writes to a System V segment with a static numeric key, allowing survival on shared hosting even when owned by a different account. Cron jobs with randomized names trigger redeployment independent of visitor traffic. This architecture extends observed trends in web malware persistence, such as database-resident shells in earlier Joomla and Drupal campaigns. The Ethereum blockchain C2 channel for payload retrieval adds operational resilience against domain takedowns. Shared memory cross-account ownership on multi-tenant hosts represents an under-addressed escalation path not covered in standard file-scanning remediation guides. Cleanup requires isolating the server, clearing shared memory segments, and rotating all credentials. Hosting providers should scan for fixed shared-memory keys and monitor mu-plugins and drop-in files for unauthorized writes. Without these steps, reinfection rates will remain high on shared infrastructure.
Sucuri: Shared hosting providers will log over 50 new SC infections per week by end of Q4 2026 unless memory segment scanning is deployed
Sources (3)
- [1]Sucuri Malware Analysis(https://sucuri.net/blog/wordpress-self-healing-mesh-backdoor)
- [2]The Hacker News Report(https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html)
- [3]WordPress Core Bootstrap Documentation(https://developer.wordpress.org/reference/hooks/)