Skip to content
Self-Healing WordPress Backdoor SC Discovered with Multiple Persistence Mechanisms

Self-Healing WordPress Backdoor SC Discovered with Multiple Persistence Mechanisms

First seen 1 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 17:05 UTC
  • •The SC malware can regenerate itself from multiple locations, complicating removal efforts.
  • •It employs advanced obfuscation techniques, making it difficult to analyze and detect.
  • •The backdoor can communicate using the Ethereum blockchain, enhancing its stealth capabilities.

A new WordPress malware, codenamed SC, has been identified, featuring a self-repairing mechanism that ensures its persistence across multiple locations, including files, the database, and shared memory. Researchers from Sucuri reported that the malware can regenerate itself even after attempts to remove it. The backdoor operates through at least eight components, including a .user.ini file that triggers a loader before every PHP request. The malware employs a complex obfuscation technique, using a substitution cipher to hide its functions. It can communicate with a command-and-control server via the Ethereum blockchain and can create hidden administrator accounts. This malware is particularly concerning due to its ability to evade traditional cleanup methods, making it a significant threat to WordPress sites. The SC backdoor is linked to CVE-2026-1581, which has a CVSS score of 7.5, indicating a high severity level.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-02-19
CVE-2026-1581 published
A high-severity vulnerability affecting WordPress was disclosed, linked to the SC backdoor.
Blog.Sucuri
Recent
SC malware identified
Researchers detailed the SC malware's self-healing capabilities and its persistence mechanisms across WordPress sites.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track SC and CVE-2026-1581 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What WordPress versions are affected?
The articles do not specify exact versions, but all WordPress sites could be at risk if they are compromised.
How does the SC malware communicate?
The SC backdoor can communicate with a command-and-control server using the Ethereum blockchain.
What should be done to mitigate this threat?
Website administrators should conduct thorough security audits and consider implementing additional security measures to detect and remove such malware.