Protect.Computer
NEWS

WordPress Backdoor Rebuilds Itself After Cleanup

· 1 min read · Got hacked Malicious byte
WordPress Backdoor Rebuilds Itself After Cleanup

Security firm Sucuri has documented a WordPress compromise, labeled “SC” after markers in the injected code, that is built to survive cleanup. The payload lives in at least eight places at once, spread across files, the database, and shared memory, and each location can rebuild the others. Delete the malicious plugin and a drop-in file rewrites it; delete the drop-in and the theme restores it; wipe every file and the next page load pulls the whole set back from the database or from a System V shared-memory segment that sits in RAM and survives file and database cleanup. Cron hooks with randomized names also trigger redeployment on a schedule.

The final payload is a backdoor that hides itself from the plugins screen and update checks, takes commands from a server whose address is looked up on the Ethereum blockchain, creates a hidden administrator account, and can run arbitrary PHP, inject JavaScript to target visitors (for example with card skimmers), and disable or delete other plugins. How the malware first gets onto a site is not yet known. Typical entry points include vulnerable plugins and themes, weak logins, supply-chain compromises of popular plugins, and insecure upload features.

How to check if you’re affected

Affected products are self-hosted WordPress sites; there is no specific plugin or WordPress version tied to this campaign yet, so check any site you administer.

  • Look in wp-content/ for unexpected db.php and advanced-cache.php drop-ins, a hex-named file such as c1b12371.php and its hidden dot-prefixed twin, and a plugin or must-use plugin named hyper-engine-kit.
  • Check your active theme’s functions.php for code you did not add; Sucuri saw the backdoor copied into a theme named khorshidi.
  • Review the Users list for administrator accounts you did not create, and review scheduled cron events for unfamiliar names.
  • Cleaning the files alone is not enough. Restore from a known-good backup or have the host remove all components together, clear any leftover shared-memory segment (ask your host), then rotate all admin, database, and hosting passwords and update every plugin and theme.

Sources

Related reading