MEDIUMMalware
Global

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

·Source: The Hacker News

Updated:

Executive Summary

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

Analysis

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
Source Attribution

Originally published by The Hacker News on Oct 1, 2026.

Related Threats