A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore those removed.
The investigation does not establish the original entry point or the number of affected websites. Once installed, however, SC abuses early loading features, themes, and plugins to maintain access. Similar hidden WordPress plugin malware shows why checking the dashboard alone can miss an infection.
Sucuri analysts identified SC during recent website cleanup work, documenting their findings on September 30, 2026. Sucuri said in a report shared with Cyber Security News (CSN) that the backdoor occupies at least eight locations and can rebuild itself after visible files are removed.
The impact extends beyond recurring malicious files. The backdoor can hide administrator accounts, collect active administrator session tokens, remove security plugins, and deliver browser scripts that could enable payment theft. The report describes these capabilities but does not quantify confirmed financial losses.
WordPress Malware Comes Back After Removal
SC survives through a network of components that repair one another. A configuration directive starts a loader before ordinary PHP requests, including requests that never reach WordPress.
A visible intermediary then loads hidden code, keeping the entry mechanism stable while concealing the main loader. The loader restores a fake plugin from an existing copy, an encoded cache backup, or a compressed recovery bundle.
Identical backdoor copies reside in ordinary and automatically loaded plugin locations. A convincing settings page helps the malicious plugin resemble a legitimate caching tool.
Two early loading components provide additional recovery routes. One embeds the complete payload as compressed, encoded data. The other searches plugin copies, shared memory, recovery archives, and the database.
An injected theme block also recreates the plugin whenever its copy disappears. This makes file deletion an incomplete response. The database holds another full payload, while supported servers retain a copy in shared memory.
Earlier persistent WordPress database backdoors likewise illustrate how malicious code can survive cleanup focused only on files. Scheduled tasks provide another route for redeployment.
The backdoor also conceals itself from plugin lists and update checks. It hides a privileged account from administrative views and can forge authentication cookies, allowing its operator to sign in without a password. Related SC variants use database triggers to recreate administrator access.
For remote instructions, SC queries smart contracts through roughly twenty public Ethereum gateways instead of relying on one fixed server.
These legitimate services act as transport. Blocking only an observed gateway leaves alternative routes available, so defenders must address the full set used.
After resolving its command endpoint, the malware sends an encrypted collection of site details and administrator session tokens. Replies can supply replacement PHP, browser scripts, or instructions to delete security plugins. This flexibility lets the operator change the infection without rebuilding its persistence network.
Cleanup and Prevention
Sucuri recommends stopping execution before removing components. First, replace the configuration’s loader target with inert content, then remove the directive.
PHP can cache that setting for up to 300 seconds, so deleting the target immediately may break every PHP request on the account. Next, remove database payloads, control settings, temporary stored values, and shared memory copies.
Clear malicious scheduled tasks and inspect database triggers before deleting hidden administrators. Unlike malware posing as protection that restores itself through scheduled execution, SC combines several independent recovery mechanisms. Shared hosting customers may need their provider’s assistance.
Remove both plugin copies, loaders, recovery archives, and malicious early loading files in one coordinated pass. Trim only the injected block from the legitimate theme.
Finish by scanning again, monitoring for returning components, closing the original entry point, and rotating exposed credentials.
Prevention requires prompt updates, a web application firewall, and regular reviews of database settings, scheduled tasks, triggers, and user accounts. Any returning file should be treated as evidence of unfinished cleanup, not as a reason to repeat the same deletion.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
