WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore those removed.

The investigation does not establish the original entry point or the number of affected websites. Once installed, however, SC abuses early loading features, themes, and plugins to maintain access. Similar hidden WordPress plugin malware shows why checking the dashboard alone can miss an infection.

Sucuri analysts identified SC during recent website cleanup work, documenting their findings on September 30, 2026. Sucuri said in a report shared with Cyber Security News (CSN) that the backdoor occupies at least eight locations and can rebuild itself after visible files are removed.

The impact extends beyond recurring malicious files. The backdoor can hide administrator accounts, collect active administrator session tokens, remove security plugins, and deliver browser scripts that could enable payment theft. The report describes these capabilities but does not quantify confirmed financial losses.

WordPress Malware Comes Back After Removal

SC survives through a network of components that repair one another. A configuration directive starts a loader before ordinary PHP requests, including requests that never reach WordPress.

A visible intermediary then loads hidden code, keeping the entry mechanism stable while concealing the main loader. The loader restores a fake plugin from an existing copy, an encoded cache backup, or a compressed recovery bundle.

Identical backdoor copies reside in ordinary and automatically loaded plugin locations. A convincing settings page helps the malicious plugin resemble a legitimate caching tool.

Two early loading components provide additional recovery routes. One embeds the complete payload as compressed, encoded data. The other searches plugin copies, shared memory, recovery archives, and the database.

An injected theme block also recreates the plugin whenever its copy disappears. This makes file deletion an incomplete response. The database holds another full payload, while supported servers retain a copy in shared memory.

Earlier persistent WordPress database backdoors likewise illustrate how malicious code can survive cleanup focused only on files. Scheduled tasks provide another route for redeployment.

The backdoor also conceals itself from plugin lists and update checks. It hides a privileged account from administrative views and can forge authentication cookies, allowing its operator to sign in without a password. Related SC variants use database triggers to recreate administrator access.

For remote instructions, SC queries smart contracts through roughly twenty public Ethereum gateways instead of relying on one fixed server.

These legitimate services act as transport. Blocking only an observed gateway leaves alternative routes available, so defenders must address the full set used.

After resolving its command endpoint, the malware sends an encrypted collection of site details and administrator session tokens. Replies can supply replacement PHP, browser scripts, or instructions to delete security plugins. This flexibility lets the operator change the infection without rebuilding its persistence network.

Cleanup and Prevention

Sucuri recommends stopping execution before removing components. First, replace the configuration’s loader target with inert content, then remove the directive.

PHP can cache that setting for up to 300 seconds, so deleting the target immediately may break every PHP request on the account. Next, remove database payloads, control settings, temporary stored values, and shared memory copies.

Clear malicious scheduled tasks and inspect database triggers before deleting hidden administrators. Unlike malware posing as protection that restores itself through scheduled execution, SC combines several independent recovery mechanisms. Shared hosting customers may need their provider’s assistance.

Remove both plugin copies, loaders, recovery archives, and malicious early loading files in one coordinated pass. Trim only the injected block from the legitimate theme.

Finish by scanning again, monitoring for returning components, closing the original entry point, and rotating exposed credentials.

Prevention requires prompt updates, a web application firewall, and regular reviews of database settings, scheduled tasks, triggers, and user accounts. Any returning file should be treated as evidence of unfinished cleanup, not as a reason to repeat the same deletion.

Indicators of compromise (IoCs):-

Type Indicator Description
Configuration file .user.ini Abused to configure execution of a loader before PHP requests. Its presence alone does not establish compromise.
Configuration file php.ini Inspect for an unauthorized prepend directive referencing the malicious loader.
Configuration file .htaccess Can contain malicious prepend settings regenerated by the backdoor.
Configuration directive auto_prepend_file Suspicious when configured to execute an unauthorized loader or hidden PHP file.
File path wp-content/c1b12371.php Observed visible intermediary that includes the hidden loader. The filename varies between sites.
File path wp-content/.c1b12371.php Observed hidden string-table loader that restores the malicious plugin. The filename varies between sites.
File path wp-content/db.php Compromised early loading component containing the compressed, encoded backdoor payload.
File path wp-content/advanced-cache.php Compromised caching component that recovers the payload from several independent sources.
File path wp-content/themes/khorshidi/functions.php Observed theme file containing an appended block that restores the malicious plugin.
File name functions.php Inspect the active theme’s file for an unauthorized block bounded by begin and end markers.
File path wp-content/mu-plugins/hyper-engine-kit.php Observed automatically loaded backdoor copy. The filename varies between sites.
File path wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php Observed duplicate backdoor disguised as a caching plugin. The filename varies between sites.
Directory wp-content/mu-plugins Check for a fake plugin matching another copy in the ordinary plugin directory.
Directory wp-content/plugins Location of the redundant ordinary plugin copy.
Directory wp-content Observed location for loaders and randomly named ZIP recovery bundles.
Directory wp-content/uploads Another location where randomly named ZIP recovery bundles may be hidden.
Code marker SC_ Prefix associated with injected begin markers. Newer components may omit recognizable markers.
Guard constant SC_AUTO_PREPEND Constant identified in the source’s component table for the hidden loader.
Database prefix sc_ Prefix associated with malicious control options and transients.
Database artifact Randomly named options row containing a large gzip and base64 blob Stores a complete payload capable of restoring the infection. No exact option name was supplied.
Recovery archive ZIP bundle with a random hexadecimal filename Payload recovery source found in content, uploads, or theme directories. No exact archive filename was supplied.
Memory artifact System V shared-memory segment containing readable PHP Off-disk payload copy that survives file deletion. The report does not disclose its numeric key.
Account artifact Hidden fully privileged administrator May be absent from dashboard lists and linked to an orphaned option containing its account ID.
Persistence artifact Malicious cron hooks and administrator-recreating database triggers Scheduled hooks support redeployment; related SC variants use triggers to restore administrator access.
Network behavior Outbound requests to public Ethereum RPC gateways Blockchain-based command-channel activity. The report supplies no exact gateway URLs or addresses.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor appeared first on Cyber Security News.