Interestana
Home/News/WordPress Backdoor Self-Heals Using Files, Database, and Memory
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

WordPress Backdoor Self-Heals Using Files, Database, and Memory

WordPress Backdoor Self-Heals Using Files, Database, and Memory

Cybersecurity researchers have detailed a sophisticated WordPress backdoor, codenamed SC, that utilizes multiple persistence mechanisms to ensure its survival and self-regeneration after attempted cleanups. This advanced malware, identified by "SC_" markers within injected content, has been described by Sucuri as a "self-healing mesh" capable of rebuilding its core components. The threat actors behind SC have implemented a multi-layered approach to maintain access to compromised WordPress sites, making traditional removal methods ineffective.

The SC backdoor's resilience stems from its ability to reconstitute itself using information stored across different parts of the compromised WordPress environment. This includes leveraging infected files, specific entries within the WordPress database, and even utilizing shared memory segments. When an administrator or security tool attempts to remove the malicious code from one location, the backdoor can detect this disruption and initiate a rebuilding process by drawing on the data it has strategically placed elsewhere. This intricate method of persistence means that simply deleting the primary backdoor file is insufficient to eradicate the threat, as the malware can effectively re-emerge from its distributed remnants.

Researchers have observed that the SC backdoor operates by injecting malicious JavaScript code into various WordPress files, including theme and plugin files, as well as core WordPress files. This injected code is designed to execute in the user's browser, often leading to further malicious activities such as redirecting users to phishing sites, serving unwanted advertisements, or initiating drive-by downloads of additional malware. The use of shared memory is particularly noteworthy, as it allows for rapid communication and coordination between different components of the backdoor, enabling swift reconstruction and adaptation.

The implications of such a self-healing backdoor are significant for WordPress site owners and administrators. Standard security practices, such as scanning for known malware signatures and removing infected files, may prove inadequate against SC. The malware's ability to persist across different data stores—files, database, and memory—necessitates a more comprehensive approach to security, including regular backups, vigilant monitoring of file integrity, and thorough analysis of database entries and server memory for any anomalies. The continuous evolution of such sophisticated persistence techniques highlights the ongoing arms race between malware developers and cybersecurity professionals in the WordPress ecosystem.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next