Cybersecurity researchers have shed light on a WordPress breach where malicious actors deployed multiple persistence mechanisms to ensure that the final payload keeps returning without having to re-infect the site. The backdoor has been codenamed SC due to the “SC_” markers present in the embedded content. Sucuri described the malware as a “self-healing grid” controlled by the blockchain.
See also: FireBox RCE: Critical vulnerability in WordPress WooCommerce plugin

“The payload lives in at least eight places at once, spread across files, the database, and shared memory, and each of these places can recreate all the others,” said security researcher Gabriel Barbosa.
“Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Purge every file on disk, and the next page load restores the entire set from the database or a shared memory section. The result is a circular system with no single point you can remove to stop it.” According to Sucuri, the malware does not have readable function names, instead using a decoder to decompress the code using a cryptographic replacement code.
A summary of the eight components is as follows:
- 1. **.user.ini**: Sets “auto_prepend_file” to run a loader before every PHP request in this directory tree.
- 2. **wp-content/c1b12371.php**: The loader that includes a hidden file with a dot prefix if it exists in the same location.
- 3. **wp-content/.c1b12371.php**: The hidden dot-prefixed file that acts as the first loader to detect a fake plugin and recreates it in mu-plugins from three sources: an existing copy in the plugins folder, a coded stub in the cache directory, and a recovery ZIP package with a random hex name.
- 4. **wp-content/db.php**: Loaded during boot and contains the entire backdoor payload in compressed, Base64-encoded form. It decodes and restores the plugin whenever it is missing or too small.
- 5.**wp-content/advanced-cache.php**: Loaded by WordPress before regular plugins when caching is enabled, it recreates the plugin from five independent sources: an existing mu-plugin, an existing plugin copy, a System V shared memory segment containing PHP, a ZIP package, and the database. It is then linked to plugins_loaded and included.
- 6. **wp-content/themes/khorshidi/functions.php**: A theme-resident twin of db.php that contains the same backdoor and rewrites the plugin whenever it is not present.
- 7. **wp-content/mu-plugins/hyper-engine-kit.php**: The actual malware that installs as both a must-use plugin and a regular plugin.
- 8. **wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php**: A copy of the same backdoor payload for redundancy. Regardless of the method used to launch the backdoor, it performs a series of actions, including hiding from the admin plugin screen or in update checks, communicating with a command and control (C2) server using the Ethereum blockchain, fingerprinting the infected website and retrieving additional payloads, creating a hidden admin account, and performing the reinfection cycle.
See also: New WordPress backdoor leads to site compromise

The backdoor’s capabilities allow the operator to take control of the WordPress site, retrieve arbitrary JavaScript to embed and target site visitors with skimmers (or other malware), execute PHP code, and disable or delete specific plugins. “On servers that support System V shared memory, the payload is written to a segment identified by a fixed numeric key,” Sucuri said.
“This part lives in RAM, so it survives file deletion and database cleanup, and on shared hosting it may even belong to a different account.” “The infection registers cron hooks, including random names along with a known fetch hook. The cron system executes the WordPress cron file, not visitor traffic, and then triggers reordering according to the schedule.” At this time, it is not known how the malware is delivered to the WordPress site.
See also: WordPress: Backdoor detected in Quick Page/Post Redirect plugin

However, typical initial access vectors include known security vulnerabilities in WordPress, plugins and themes, weak login credentials, software supply chain attacks targeting popular plugins.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
