Advanced WordPress Backdoor Utilizes Multi-Vector Persistence via Files, Database, and Shared Memory
A sophisticated WordPress backdoor employs multi-vector persistence across files, database, and shared memory to self-repair after cleanup, leveraging blockchain for command-and-control communications. The malware's self-healing architecture spans eight components, including encoded payloads and System V shared memory segments, making eradication challenging.
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.
The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
*** END OF TRANSMISSION ***