Ethical Hacking News
Unraveling the Enigmatic Self-Healing Mesh: A Highly Elusive and Resilient Malware has been identified, dubbed SC, which utilizes a complex persistence mechanism that renders it highly resilient to deletion. The malware has been linked to multiple initial access vectors, and its abilities include taking control of WordPress sites, injecting malware into site visitors, and deactivating or deleting plugins.
The SC malware is a highly resilient and self-healing mesh that uses a blockchain-controlled persistence mechanism to evade detection. The malware has multiple components spread across eight disparate locations, making it challenging to eradicate. The SC malware uses a substitution cipher to avoid readable function names, making it difficult for security researchers to develop an effective countermeasure. The malware has been linked to various initial access vectors, including known security flaws, weak login credentials, and software supply chain attacks. The malware can take control of WordPress sites, inject malware into site visitors, and deactive plugins, making it a significant threat.
The realm of cybersecurity is fraught with numerous challenges, as adversaries continually strive to devise innovative methods to breach the robust defenses of modern computing systems. Recently, cybersecurity researchers have shed light on a particularly insidious WordPress compromise, wherein threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. This phenomenon has been codenamed SC, and Sucuri has aptly described the malware as a "self-healing mesh" that is blockchain-controlled.
The payload, which is spread across eight disparate locations, can rebuild itself in all instances, rendering the deletion of any one component ineffective in eliminating the malware. The researcher Gabriel Barbosa succinctly elucidated this concept, stating, "The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others." This circular system, with no single point of vulnerability, poses a formidable challenge to security practitioners seeking to eradicate the malware.
The SC malware, as it has come to be known, does not possess any readable function names, instead relying on a decoder to unscramble the code utilizing a substitution cipher. This makes it particularly difficult for security researchers to develop an effective countermeasure against the malware. The eight components of the SC malware are as follows:
- .user.ini, which sets "auto_prepend_file" to run a loader before every PHP request in that directory tree.
- wp-content/c1b12371.php, the loader that includes a hidden dot-prefixed file if it exists in the same location.
- wp-content/.c1b12371.php, the hidden dot-prefixed file which acts as the first-stage loader to locate a fake plugin and rebuilds it in mu-plugins from three sources: an existing copy in the plugins folder, an encoded stub in the cache directory, and a ZIP restore bundle with a random hex name.
- wp-content/db.php, which is loaded during bootstrap and carries the entire backdoor payload in compressed, Base64-encoded format. It decodes and re-deploys the plugin whenever it's missing or too small.
- wp-content/advanced-cache.php, which is loaded by WordPress before ordinary plugins when caching is enabled, and rebuilds the plugin from five independent sources: an existing mu-plugin, an existing plugin copy, a System V shared-memory segment holding PHP, a ZIP bundle, and the database. It then hooks plugins_loaded and includes it.
- wp-content/themes/khorshidi/functions.php, a theme-resident twin of db.php that features the same backdoor and rewrites the plugin every time it is not present.
- wp-content/mu-plugins/hyper-engine-kit.php, the actual malware that's installed as both a must-use plugin and a normal plugin.
- wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php, a duplicate of the same backdoor payload for redundancy.
Regardless of the method used to launch the backdoor, it carries out a number of actions, including hiding itself from the admin plugins screen or in update checks, communicating with a command-and-control (C2) server using the Ethereum blockchain, fingerprinting the infected site and retrieving additional payloads, creating a hidden administrator account, and running the reinfection loop.
The backdoor's capabilities allow the operator to take control of the WordPress site, fetch arbitrary JavaScript to inject and target site visitors with skimmers (or other malware), run PHP code, and deactivate or delete specific plugins. The malware's resilience is further enhanced by the fact that it can survive file deletion and database cleanup alike, thanks to its presence in System V shared memory.
The SC malware has been attributed to a number of initial access vectors, including known security flaws in WordPress, plugins, and themes; weak login credentials; software supply chain attacks targeting popular plugins; and the exploitation of insecure media or form upload features to push PHP web shells into server directories.
The disclosure of the SC malware comes as a high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin has come under active exploitation. The issue affects all versions of the plugin up to, and including, 2.4.14.
Unraveling the Enigmatic Self-Healing Mesh: A Highly Elusive and Resilient Malware has been identified, dubbed SC, which utilizes a complex persistence mechanism that renders it highly resilient to deletion. The malware has been linked to multiple initial access vectors, and its abilities include taking control of WordPress sites, injecting malware into site visitors, and deactivating or deleting plugins.
Related Information:
https://www.ethicalhackingnews.com/articles/Unraveling-the-Enigmatic-Self-Healing-Mesh-The-WordPress-Backdoor-Rebuilds-Itself-After-Cleanup-Using-Files-Database-and-Shared-Memory-ehn.shtml
https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html
Published: Thu Oct 1 11:52:59 2026 by llama3.2 3B Q4_K_M