Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica
    • Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media
    • Saudi-led coalition accuses Houthis of striking Medina power station
    • Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO
    • Whatever AI Safety Is, It’s Not This
    • A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End
    • Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
    • Frank Holmes: They Will Print $100 Trillion
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 01, 2026Vulnerability / Web Security

    Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.

    The backdoor has been codenamed SC after the “SC_” markers present in the injected content. Sucuri has described the malware as a “self-healing mesh” that’s blockchain-controlled.

    “The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others,” security researcher Gabriel Barbosa said.

    “Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it.”

    Cybersecurity

    According to Sucuri, the malware does not have any readable function names, instead employing a decoder to unscramble the code using a substitution cipher. A summary of the eight components is as follows –

    • .user.ini, which sets “auto_prepend_file” to run a loader before every PHP request in that directory tree.
    • wp-content/c1b12371.php, the loader that includes a hidden dot-prefixed file if it exists in the same location.
    • wp-content/.c1b12371.php, the hidden dot-prefixed file which acts as the first-stage loader to locate a fake plugin and rebuilds it in mu-plugins from three sources: an existing copy in the plugins folder, an encoded stub in the cache directory, and a ZIP restore bundle with a random hex name.
    • wp-content/db.php, which is loaded during bootstrap and carries the entire backdoor payload in compressed, Base64-encoded format. It decodes and re-deploys the plugin whenever it’s missing or too small.
    • wp-content/advanced-cache.php, which is loaded by WordPress before ordinary plugins when caching is enabled, and rebuilds the plugin from five independent sources: an existing mu-plugin, an existing plugin copy, a System V shared-memory segment holding PHP, a ZIP bundle, and the database. It then hooks plugins_loaded and includes it.
    • wp-content/themes/khorshidi/functions.php, a theme-resident twin of db.php that features the same backdoor and rewrites the plugin every time it is not present.
    • wp-content/mu-plugins/hyper-engine-kit.php, the actual malware that’s installed as both a must-use plugin and a normal plugin.
    • wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php, a duplicate of the same backdoor payload for redundancy.

    Regardless of the method used to launch the backdoor, it carries out a number of actions, including hiding itself from the admin plugins screen or in update checks, communicating with a command-and-control (C2) server using the Ethereum blockchain, fingerprinting the infected site and retrieving additional payloads, creating a hidden administrator account, and running the reinfection loop.

    The backdoor’s capabilities allow the operator to take control of the WordPress site, fetch arbitrary JavaScript to inject and target site visitors with skimmers (or other malware), run PHP code, and deactivate or delete specific plugins.

    “On servers that support System V shared memory, the payload is written into a segment identified by a fixed numeric key,” Sucuri said. “That segment lives in RAM, so it survives file deletion and database cleanup alike, and on shared hosting it can even be owned by a different account.”

    “The infection registers cron hooks, including randomized names alongside a known fetch hook. System cron runs the WordPress cron file, not visitor traffic, then triggers redeployment on schedule.”

    Cybersecurity

    It’s currently not known how the malware is delivered to the WordPress site. However, typical initial access vectors include known security flaws in WordPress, plugins, and themes; weak login credentials; software supply chain attacks targeting popular plugins; and the exploitation of insecure media or form upload features to push PHP web shells into server directories.

    “SC is a reminder that a modern WordPress infection can be a system rather than a file,” Sucuri said. “This toolkit spreads identical copies of one backdoor across drop-ins, the theme, a fake plugin in two locations, the database, and shared memory, hides its command channel inside legitimate blockchain infrastructure, and rewrites itself from any surviving copy on the very next request.”

    wpForo Forum WordPress Plugin Flaw Exploited

    The disclosure comes as a high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin (CVE-2026-1581, CVSS score: 7.5) has come under active exploitation. The issue affects all versions of the plugin up to, and including, 2.4.14.

    According to telemetry data from Previdian, fewer than 20 exploitation attempts targeting the vulnerability have been observed since July 3, 2026. The activity has originated from five unique attacker IP addresses located in Bulgaria, Switzerland, France, the U.S., and Yemen.

    Backdoor Cleanup Database Files memory rebuilds shared WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Alleged KillSec Ransomware Mastermind a 16-Year-Old

    ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

    Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

    Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026

    Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.