Thehackernews Self-Healing WordPress Backdoor SC Discovered with Multiple Persistence Mechanisms
Article Content
- •The SC malware can regenerate itself from multiple locations, complicating removal efforts.
- •It employs advanced obfuscation techniques, making it difficult to analyze and detect.
- •The backdoor can communicate using the Ethereum blockchain, enhancing its stealth capabilities.
A new WordPress malware, codenamed SC, has been identified, featuring a self-repairing mechanism that ensures its persistence across multiple locations, including files, the database, and shared memory. Researchers from Sucuri reported that the malware can regenerate itself even after attempts to remove it. The backdoor operates through at least eight components, including a .user.ini file that triggers a loader before every PHP request. The malware employs a complex obfuscation technique, using a substitution cipher to hide its functions. It can communicate with a command-and-control server via the Ethereum blockchain and can create hidden administrator accounts. This malware is particularly concerning due to its ability to evade traditional cleanup methods, making it a significant threat to WordPress sites. The SC backdoor is linked to CVE-2026-1581, which has a CVSS score of 7.5, indicating a high severity level.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track SC and CVE-2026-1581 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What WordPress versions are affected?
How does the SC malware communicate?
What should be done to mitigate this threat?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…