Full Report
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
Analysis Summary
# Tool/Technique: SC WordPress Backdoor
## Overview
The **SC Backdoor** (named after "SC_" markers in its code) is a highly sophisticated, "self-healing mesh" malware designed for WordPress environments. Its primary purpose is to maintain persistent access to a compromised web server through a circular redundancy system. It ensures that if any single component of the malware is deleted—whether from the file system, database, or memory—the remaining components automatically rebuild the missing pieces.
## Technical Details
- **Type:** Malware Family / Persistence Framework
- **Platform:** WordPress (PHP/Linux-based web servers)
- **Capabilities:** Self-healing/Redundancy, Blockchain-based C2, Shared Memory Persistence, Credential Theft (Hidden Admin), Arbitrary Code Execution.
- **First Seen:** Reported October 2026 (via Sucuri)
## MITRE ATT&CK Mapping
- **TA0003 - Persistence**
- T1505.003 - Server Software Component: Web Shell
- T1133 - External Remote Services
- T1136.001 - Create Account: Local Account (Hidden WordPress Admin)
- **TA0005 - Defense Evasion**
- T1564 - Hide Artifacts
- T1027 - Obfuscated Files or Information (Substitution cipher)
- T1140 - Deceptive File Names/Paths
- **TA0011 - Command and Control**
- T1102.003 - Web Service: One-Way Communication (Blockchain-based C2)
## Functionality
### Core Capabilities
- **Redundant Reinfection Loop:** The malware resides in eight distinct locations. If one is removed, the others (loaders, drop-ins, or database entries) trigger a rewrite of the missing component.
- **Shared Memory Persistence:** Utilizes **System V shared memory** segments (RAM) to store the payload. This allows the malware to survive full disk cleanups and database wipes, as the payload persists in volatile memory until a server reboot or manual memory clearing.
- **Blockchain C2:** Uses the Ethereum blockchain infrastructure to receive commands or updates, making the command channel difficult to block or take down.
- **Stealth:** Automatically hides itself from the WordPress "Active Plugins" list and suppresses update checks to avoid detection by site administrators.
### Advanced Features
- **Auto-Prepend Execution:** Uses `.user.ini` to force the PHP engine to run the malware loader before every single request in the directory tree.
- **Multi-Source Rebuilding:** Components like `advanced-cache.php` can rebuild the core payload from five different sources: existing plugins, mu-plugins, System V shared memory, ZIP bundles, or the database.
- **Hidden Admin Creation:** Automatically generates a hidden administrator account for direct access.
- **Payload Delivery:** Can fetch and inject arbitrary JavaScript (e.g., credit card skimmers) or execute arbitrary PHP code.
## Indicators of Compromise
### File Names
- `.user.ini` (modified to include `auto_prepend_file`)
- `wp-content/c1b12371.php` (Loader)
- `wp-content/.c1b12371.php` (Hidden First-stage Loader)
- `wp-content/db.php` (Backdoor container)
- `wp-content/advanced-cache.php` (Backdoor container)
- `wp-content/mu-plugins/hyper-engine-kit.php`
- `wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php`
- Randomly named ZIP files (e.g., `[hex-string].zip`) used for restoration.
### Network Indicators
- **C2:** Ethereum blockchain infrastructure (used for command retrieval).
### Behavioral Indicators
- Presence of "SC_" markers in PHP files.
- Unauthorized creation of administrator accounts not visible in the standard GUI.
- Unexpected System V shared memory segments (identifiable via `ipcs -m`).
- Automated rewriting of deleted files within `wp-content` or `mu-plugins` directories.
## Associated Threat Actors
- **Unknown** (Current research refers to the toolkit by the codename "SC").
## Detection Methods
- **Behavioral Detection:** Monitor for unauthorized file modifications in the `wp-content` directory, specifically `db.php` and `advanced-cache.php`.
- **Memory Analysis:** Scan System V shared memory segments for encoded PHP stubs or the "SC_" marker.
- **Database Inspection:** Check the WordPress options table for large, Base64-encoded strings or serialized data containing the reconstruction stubs.
- **Integrity Checking:** Use tools to verify the integrity of the WordPress core and active theme files (specifically `functions.php`).
## Mitigation Strategies
- **Server Hardening:** Disable `allow_url_fopen` and `allow_url_include` if not required.
- **PHP Configuration:** Restrict the use of `auto_prepend_file` in `.user.ini` by configuring the web server to ignore user-defined INI files.
- **Filesystem Permissions:** Set strict "read-only" permissions on the WordPress root and `wp-content` directories, allowing "write" access only during controlled updates.
- **Memory Management:** Regularly flush or monitor shared memory segments if the hosting environment allows.
- **Credential Hygiene:** Enforce MFA for all admin accounts and regularly audit the user list via CLI (`wp-cli user list`) to find hidden accounts.
## Related Tools/Techniques
- **Web Shells:** Similar to generic PHP backdoors but with significantly higher persistence.
- **Steganography/Encoding:** Uses substitution ciphers and Base64/Compression to evade signature-based AV.
- **Fileless Malware:** The use of shared memory segments aligns with fileless execution techniques.