WordPress backdoor SC rebuilds itself after cleanup
Sucuri detailed a WordPress compromise in which attackers deployed the SC backdoor with multiple persistence mechanisms — files, the database and shared memory — allowing the payload to return after removal. The malware is described as a "self-healing mesh".
- Backdoor codenamed SC after "SC_" markers in injected content
- Persistence relies on files, database and shared memory
- Payload returns after cleanup without reinfecting the site
Read next
Security