hacker-news · Crawled Oct 1, 2026
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
8 IoCs
Read original article ↗
AI Summary
A sophisticated WordPress backdoor named SC has been identified, utilizing a self-healing mesh of persistence mechanisms across files, database entries, and shared memory segments to resist removal. The malware, which hides using obfuscated code and a substitution cipher decoder, is capable of rebuilding itself from any surviving component, including hidden files, mu-plugins, themes, and System V shared memory. It can communicate with a C2 server via the Ethereum blockchain, create hidden admin accounts, inject malicious JavaScript, and execute arbitrary PHP code. The backdoor spreads identical payloads across multiple locations, ensuring reinfection even after partial cleanup.
AI-extracted · verify before operational use
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | .user.ini | Details → |
| Filename | wp-content/c1b12371.php | Details → |
| Filename | wp-content/.c1b12371.php | Details → |
| Filename | wp-content/db.php | Details → |
| Filename | wp-content/advanced-cache.php | Details → |
| Filename | wp-content/themes/khorshidi/functions.php | Details → |
| Filename | wp-content/mu-plugins/hyper-engine-kit.php | Details → |
| Filename | wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php | Details → |