Back to Feed
MalwareOct 1, 2026

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

WordPress backdoor rebuilds itself using files, database, and shared memory after cleanup.

Summary

A sophisticated WordPress backdoor, codenamed SC, has been discovered that employs a 'self-healing mesh' of persistence mechanisms. The malware resides in at least eight locations across files, the database, and shared memory, allowing any component to rebuild the others if deleted. This makes traditional cleanup methods ineffective, as the backdoor can restore itself from various sources, including RAM-based shared memory segments.

Full text

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory Ravie LakshmananOct 01, 2026Vulnerability / Web Security Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's blockchain-controlled. "The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others," security researcher Gabriel Barbosa said. "Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it." According to Sucuri, the malware does not have any readable function names, instead employing a decoder to unscramble the code using a substitution cipher. A summary of the eight components is as follows - .user.ini, which sets "auto_prepend_file" to run a loader before every PHP request in that directory tree. wp-content/c1b12371.php, the loader that includes a hidden dot-prefixed file if it exists in the same location. wp-content/.c1b12371.php, the hidden dot-prefixed file which acts as the first-stage loader to locate a fake plugin and rebuilds it in mu-plugins from three sources: an existing copy in the plugins folder, an encoded stub in the cache directory, and a ZIP restore bundle with a random hex name. wp-content/db.php, which is loaded during bootstrap and carries the entire backdoor payload in compressed, Base64-encoded format. It decodes and re-deploys the plugin whenever it's missing or too small. wp-content/advanced-cache.php, which is loaded by WordPress before ordinary plugins when caching is enabled, and rebuilds the plugin from five independent sources: an existing mu-plugin, an existing plugin copy, a System V shared-memory segment holding PHP, a ZIP bundle, and the database. It then hooks plugins_loaded and includes it. wp-content/themes/khorshidi/functions.php, a theme-resident twin of db.php that features the same backdoor and rewrites the plugin every time it is not present. wp-content/mu-plugins/hyper-engine-kit.php, the actual malware that's installed as both a must-use plugin and a normal plugin. wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php, a duplicate of the same backdoor payload for redundancy. Regardless of the method used to launch the backdoor, it carries out a number of actions, including hiding itself from the admin plugins screen or in update checks, communicating with a command-and-control (C2) server using the Ethereum blockchain, fingerprinting the infected site and retrieving additional payloads, creating a hidden administrator account, and running the reinfection loop. The backdoor's capabilities allow the operator to take control of the WordPress site, fetch arbitrary JavaScript to inject and target site visitors with skimmers (or other malware), run PHP code, and deactivate or delete specific plugins. "On servers that support System V shared memory, the payload is written into a segment identified by a fixed numeric key," Sucuri said. "That segment lives in RAM, so it survives file deletion and database cleanup alike, and on shared hosting it can even be owned by a different account." "The infection registers cron hooks, including randomized names alongside a known fetch hook. System cron runs the WordPress cron file, not visitor traffic, then triggers redeployment on schedule." It's currently not known how the malware is delivered to the WordPress site. However, typical initial access vectors include known security flaws in WordPress, plugins, and themes; weak login credentials; software supply chain attacks targeting popular plugins; and the exploitation of insecure media or form upload features to push PHP web shells into server directories. "SC is a reminder that a modern WordPress infection can be a system rather than a file," Sucuri said. "This toolkit spreads identical copies of one backdoor across drop-ins, the theme, a fake plugin in two locations, the database, and shared memory, hides its command channel inside legitimate blockchain infrastructure, and rewrites itself from any surviving copy on the very next request." wpForo Forum WordPress Plugin Flaw Exploited The disclosure comes as a high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin (CVE-2026-1581, CVSS score: 7.5) has come under active exploitation. The issue affects all versions of the plugin up to, and including, 2.4.14. According to telemetry data from Previdian, fewer than 20 exploitation attempts targeting the vulnerability have been observed since July 3, 2026. The activity has originated from five unique attacker IP addresses located in Bulgaria, Switzerland, France, the U.S., and Yemen. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Malware, Vulnerability, Web Security, WordPress ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Indicators of Compromise

  • malware — SC

Entities

WordPress (product)Sucuri (vendor)PHP (technology)System V shared memory (technology)Ethereum blockchain (technology)