Understanding SC Malware: Why WordPress Sites Reinfect After Cleanup

A new WordPress malware campaign analyzed by Sucuri found that deleting a few suspicious files was no longer enough to clean up the website. Named Malware SC can maintain at least eight copies and recovery mechanisms in files, databases, recurring tasks, and shared storage, thus manually reconstructing the entire system after each incomplete cleanup by the administrator.

SC malware creates multiple persistence layers in WordPress
SC malware distributes persistence across multiple WordPress components. Image from the original analysis: The Hacker News.

SC Malware Is Not a Single File

According to the report published on September 30, 2026 by researcher Gabriel Barbosa in Sucuri, SC is named after the “SC_” signs in the inserted code. The most notable point is the circular architecture: each living component can restore those that have been deleted. So scanning and deleting a plugin or backdoor seen on the drive only handles the superficial part of the problem.

Eight Locations Work Together to Self-Heal

Abutment chain starting from the indicator auto_prepend_file trong .user.ini, forcing PHP to run a loader before every request. This loader calls a hidden file in the wp-content. Song song, hai drop-in db.php and advanced-cache.phpa code fragment implanted in functions.php of the interface, the same two dummy plugin copies can in turn reconstruct the payload.

Report fake plugin records that appear even in the folder mu-plugins and plugins. The must-use copy is automatically loaded by WordPress and usually does not appear like a regular plugin, while the other creates a backup layer. File names can vary between websites, so it's not enough to just follow a fixed marker.

Persistence Also Lives Off Disk

The SC saves a compressed and encoded copy of the Base64 payload in the WordPress options table. On the server that supports System V shared memory, the PHP code is also kept in a RAM region with a fixed key. Cron tasks and, in some related variations, database triggers can redeploy malicious code or regenerate administrative accounts.

This explains why replacing an entire website file with a clean copy can still fail: the next web request to go through the leftover drop-in will read the load from the database or shared memory and then write the files back.

A Command Channel Hidden in Ethereum Infrastructure

Instead of relying on a single control server, the backdoor carries a list of about 20 public Ethereum RPC gateways and reads instructions from the smart contract. Taking advantage of the legal blockchain infrastructure helps operators have multiple redundant lines; blocking an individual address does not disable the communication channel.

The payload can collect URLs, WordPress versions and plugins, themes in use, mu-plugin lists and admin session tokens. It can also receive JavaScript to insert into the interface, install new PHP, disable security plugins, create hidden admins, and forge authentication cookies.

Key Indicators of Compromise

Administrators should review directives auto_prepend_file anomaly; strange PHP code in db.php, advanced-cache.php hoặc cuối functions.php; the two plugins have the same content in mu-plugins and plugins; random name ZIP file; option record containing large blob; administrator has privileges but does not appear in the list; same connection goes to public Ethereum RPCs.

Cleanup Order Determines the Outcome

Sucuri recommends first securely disabling the prepend mechanism, as this value can be cached by PHP and deleting the wrong target can cause any PHP request to fail. Then it is necessary to remove the off-disk load in the database and shared memory, remove the malicious cron and database trigger, and then process the hidden account and the entire file in one go.

After cleaning, the website must be scanned and monitored for links that have been implanted with code. If the file reappears, there is still a pivot point or the original access route that has not been closed. Admins also need to update the core, plugins, and interface, cycle through credentials that may have been exposed, and review the web application firewall.

Lessons for WordPress Operations

The SC incident suggests that a modern intrusion should be viewed as a system rather than a malicious file. Investigation must cover drives, databases, memory, recurring tasks, accounts, and outbound traffic. Sustainable restoration is only achieved when every load copy is discarded in the correct order and the initial gap is remedied.

VNCyberS compiled from Sucuri and The Hacker News

Contact Us

Email: [email protected]
Phone: +84 903260277