Self-healing WordPress backdoor uses shared memory and blockchain C2
A new WordPress malware variant called SC persists across files, database, and RAM, rebuilding itself from multiple sources to evade cleanup.
Security researchers have identified a sophisticated WordPress backdoor that resists removal by spreading its payload across eight different locations, including system memory. Codenamed SC, this malware creates a self-healing mesh that restores itself from the database or RAM even after all visible files are deleted.
What happened
The malware, analyzed by Sucuri, operates as a circular system with no single point of failure. Security researcher Gabriel Barbosa noted that deleting one component triggers another to rewrite it, ensuring the backdoor remains active. The payload exists simultaneously in files, the database, and shared memory, allowing any surviving copy to rebuild the entire infection on the next page load.
This specific strain does not use readable function names. Instead, it employs a substitution cipher decoder to unscramble its code at runtime. The infection hides its presence from admin screens and update checks while maintaining communication with a command-and-control server via the Ethereum blockchain. It also creates hidden administrator accounts and can inject JavaScript skimmers to target site visitors.
The disclosure coincides with active exploitation of a high-severity SQL injection flaw in the wpForo Forum plugin, tracked as CVE-2026-1581. This vulnerability affects versions up to 2.4.14 and has a CVSS score of 7.5. Telemetry from Previdian shows fewer than 20 exploitation attempts since July 3, 2026, originating from IP addresses in Bulgaria, Switzerland, France, the U.S., and Yemen.
How it works
The SC backdoor relies on redundancy across eight specific components. It starts with .user.ini, which forces PHP to run a loader before every request. This loader finds a hidden dot-prefixed file that acts as the first stage, locating a fake plugin named hyper-engine-kit. If the plugin is missing, the loader rebuilds it from three sources: an existing copy, an encoded stub in the cache, or a ZIP bundle.
Two drop-in files, db.php and advanced-cache.php, serve as critical persistence layers. db.php holds the compressed, Base64-encoded payload and redeploys it if the plugin is absent or too small. advanced-cache.php performs a similar function but draws from five sources, including a System V shared-memory segment. This RAM-based storage survives file deletion and database cleanup, making it particularly difficult to eradicate on shared hosting environments.
The theme file functions.php and the duplicate plugin files act as further backups. Once active, the malware registers cron hooks with randomized names. These hooks trigger redeployment on a schedule via the system cron, independent of visitor traffic. The command channel uses legitimate blockchain infrastructure to hide its communications, fetching additional payloads or executing arbitrary PHP code as directed by the operator.
Key details
- The malware is codenamed SC due to "SC_" markers in the injected content.
- It persists in at least eight locations, including files, database, and System V shared memory.
- Communication with the command-and-control server is hidden within Ethereum blockchain transactions.
- The payload uses a substitution cipher to obscure function names and logic.
- Redeployment is triggered by scheduled cron jobs, not just user requests.
- Active exploitation of wpForo plugin CVE-2026-1581 has been observed from five unique IPs.
Why it matters
For developers and site administrators, this incident highlights that modern infections are systems rather than simple files. Traditional cleanup methods that focus on scanning disk files for known signatures are insufficient against threats that store payloads in RAM or database entries. If you delete the visible malware but leave the database or shared memory segment intact, the site will reinfect itself immediately.
The use of blockchain for command-and-control further complicates detection. By hiding instructions within legitimate public ledger transactions, the attackers avoid traditional network signature detection. This means security tools must look for behavioral anomalies, such as unexpected outbound requests or unauthorized admin account creation, rather than just blocking known malicious domains.
What you can do
- Audit your WordPress installation for unknown mu-plugins and drop-in files like
db.php. - Check for hidden administrator accounts and remove any that were not created by your team.
- Inspect System V shared memory segments on your server if you suspect compromise.
- Update the wpForo Forum plugin to a version newer than 2.4.14 to patch CVE-2026-1581.
- Monitor cron jobs for randomized or unfamiliar hooks that may trigger malware redeployment.
- Implement file integrity monitoring to detect unauthorized changes to core WordPress files.

