SC WordPress Malware Uses Self-Rebuilding Loaders and Blockchain-Controlled Backdoor

Summary
Researchers analyzed SC malware that keeps reinfecting WordPress sites through mutually restoring files, database copies, and shared memory. Its backdoor hides an admin account, disables security plugins, and retrieves instructions via public Ethereum RPC gateways.
Key points
- The malware persists across WordPress drop-ins, theme code, hidden loaders, duplicate fake plugins, database options, shared memory, scheduled tasks, and—in related variants—database triggers.
- Components restore one another, so deleting visible files alone can trigger rapid reinfection.
- The backdoor hides itself and an administrator account, can forge login cookies, and can disable or delete security plugins.
- It contacts smart contracts through a rotating list of public Ethereum RPC gateways and can retrieve PHP or front-end JavaScript, including code capable of checkout skimming.
- Indicators include unexpected SC-marked PHP blocks, auto_prepend_file directives, duplicate fake plugins, encoded database payloads, hidden admin accounts, and outbound Ethereum RPC traffic.
- Cleanup requires disabling the prepend execution safely, removing off-disk payloads and scheduled tasks, checking for database triggers, then removing malicious files and monitoring for recurrence.
Article Details
- Attack Vectors
- The initial entry method was not disclosed.
- A .user.ini auto_prepend_file directive runs a PHP shim before requests, including requests that do not reach WordPress; the shim includes a hidden loader.
- WordPress drop-ins, an injected theme block, and duplicate fake-plugin installations restore and execute the backdoor when another copy is removed.
- Payload copies in a database options row, System V shared memory, and a ZIP restore bundle provide additional recovery sources. Scheduled cron hooks can trigger redeployment.
- The backdoor reads instructions through public Ethereum RPC gateways, then sends site information and administrator session tokens to a resolved endpoint. Responses can supply injected JavaScript, new PHP, and instructions to remove security plugins.
- Defensive Notes
- Neutralize the PHP prepend target before removing its directive; deleting a still-cached target can cause PHP requests to fail.
- Stop execution and remove database and shared-memory payload copies, control options, scheduled tasks, and any administrator-recreating database triggers before cleaning files.
- Remove the hidden administrator, loaders, restore bundle, fake-plugin copies, malicious drop-ins, and the bounded injection in the theme’s functions.php in one pass.
- Rescan and monitor for recreated files; investigate any surviving persistence or entry point and rotate credentials the attacker could have accessed.
- Keep components patched, use a Web Application Firewall, and regularly audit options, scheduled tasks, database triggers, and user accounts.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationSC components conceal function names with scrambled string tables and a positional substitution decoder; payload copies also use gzip and base64 encoding.T1041 · Exfiltration Over C2 ChannelThe backdoor encrypts site details and current administrator session tokens and posts them to its resolved endpoint.T1053.003 · CronThe infection registers cron hooks that can trigger redeployment when system cron runs the WordPress cron file.T1102.001 · Dead Drop ResolverThe backdoor reads smart-contract instructions through public Ethereum RPC gateways to resolve an endpoint used for further communication.T1136 · Create AccountThe backdoor can create a hidden, fully privileged WordPress administrator, including by writing directly to the users and usermeta tables.T1505.003 · Web ShellSC installs a PHP backdoor as WordPress must-use and normal plugin copies, allowing remote control through the compromised site.T1546 · Event Triggered ExecutionA .user.ini auto_prepend_file directive makes the SC loader run before PHP requests in the affected directory tree.T1550.004 · Web Session CookieThe backdoor forges valid authentication cookies for its hidden administrator so the operator can log in without a password.T1562.001 · Disable or Modify ToolsInstructions returned to the backdoor can cause it to deactivate and delete security plugins.T1564.001 · Hidden Files and DirectoriesA dot-prefixed PHP file hides the real loader beside a plainly named shim.
Malware
Products
EthereumRather than a single hardcoded server, the payload carries a list of roughly twenty public Ethereum RPC gateways and a set of smart-contract method selectors. It sends requests to those gateways to readPHPThe .user.ini trigger. A single line, auto_prepend_file, points PHP at a loader that runs before every request in that directory tree. This fires even on requests that never reach WordPress. The value is cached by PHP.WordPressDuring recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this