SC is a WordPress backdoor ecosystem that survives by regenerating itself across files, the database, shared memory, and scheduled tasks, making simple file deletion ineffective. Its payload hides from admin views, communicates through public Ethereum RPC gateways, and can recreate privileged access, security changes, and even checkout-skimming code on demand. #SC #WordPress #EthereumRPC
Keypoints
- The malware family SC persists through a circular mesh of at least eight components that can rebuild one another after removal.
- Persistence exists not only in files, but also in the WordPress database, System V shared memory, scheduled cron hooks, and database triggers.
- The infection uses .user.ini auto_prepend_file, hidden shim files, db.php, advanced-cache.php, and theme injection to restore the payload.
- The backdoor hides itself from WordPress admin views and update checks, and can forge authentication cookies for a hidden administrator account.
- Command and control traffic is routed through roughly twenty public Ethereum RPC gateways and smart-contract method selectors instead of a single server.
- The payload can deploy front-end JavaScript for checkout skimming, install new PHP, disable security plugins, and recreate deleted access.
- Effective cleanup requires disabling execution first, removing off-disk and on-disk persistence in the correct order, and then rescanning for regenerated components.
MITRE Techniques
- [T1053.005 ] Scheduled Task/Job: Cron – The infection registers cron hooks so system cron can redeploy the malware on schedule (‘System cron runs the WordPress cron file … then triggers redeployment on schedule’).
- [T1098 ] Account Manipulation – The payload creates or adopts a hidden administrator and can write the account directly into the users and usermeta tables (‘It creates a hidden administrator … writing the account directly into the users and usermeta tables’).
- [T1036 ] Masquerading – The malware disguises itself as a legitimate caching plugin and hides its presence from admin views (‘a convincing fake settings page … suggests a real caching plugin’; ‘it filters the plugin list … to remove its own entry’).
- [T1112 ] Modify Registry/Configuration or equivalent application configuration abuse – It changes WordPress configuration mechanisms such as auto_prepend_file and injected drop-ins to gain execution before normal code (‘auto_prepend_file points PHP at a loader that runs before every request’).
- [T1505.003 ] Server Software Component: Web Shell – The malicious PHP components in db.php, advanced-cache.php, and related drop-ins act as server-side web backdoors (‘carries the full backdoor as a gzip plus base64 blob’; ‘rebuilds the plugin’).
- [T1027 ] Obfuscated Files or Information – Files are heavily obfuscated with scrambled strings and a decoder to hide functionality (‘table of scrambled strings and a small decoder’).
- [T1027.009 ] Embedded Payloads – The payload is embedded inside drop-ins and encoded blobs, then decoded and written back to disk (‘decodes the blob and writes the plugin straight back to disk’).
- [T1070.004 ] File Deletion – The malware can wipe security plugins and remove directories to hinder defense (‘it can deactivate it, wipe its directory’).
- [T1012 ] Query Registry – The payload enumerates and uses WordPress state such as versions, themes, plugins, and session tokens before exfiltration (‘It collects the site URL and host, the WordPress and plugin versions…’).
- [T1041 ] Exfiltration Over C2 Channel – It posts collected site data to its endpoint before receiving instructions (‘encrypts that bundle, and posts it to the resolved endpoint’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The malware communicates over web requests, including public Ethereum RPC gateways used as a command channel (‘requests to those gateways to read instructions from a smart contract’).
- [T1562.001 ] Impair Defenses: Disable or Modify Tools – It deactivates and removes security plugins to reduce detection and protection (‘it can deactivate it, wipe its directory’).
Indicators of Compromise
- [File paths / filenames] Malicious drop-ins and loaders in WordPress directories – wp-content/db.php, wp-content/advanced-cache.php, wp-content/c1b12371.php, wp-content/.c1b12371.php
- [File paths / filenames] Fake plugin and duplicate payload locations – wp-content/mu-plugins/hyper-engine-kit.php, wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php
- [File paths / filenames] Theme injection and restore bundles – wp-content/themes/khorshidi/functions.php, random-hex ZIP restore bundle in wp-content or uploads
- [Configuration files] Execution-prepended directives and loaders – .user.ini, php.ini, .htaccess with auto_prepend_file pointing to a hidden dot-prefixed PHP file
- [Database artifacts] Persistence stored in WordPress options and user tables – random-name options row with gzip+base64 payload, default capabilities meta key, orphaned option pointing to admin ID
- [Shared memory] In-memory payload copy used for reinfection – System V shared-memory segment containing readable PHP starting with an opening tag
- [Scheduled tasks / triggers] Automated redeployment mechanisms – malicious cron hooks with randomized names and database triggers that recreate an administrator
- [Network indicators] Command channel infrastructure – public Ethereum RPC gateways used for outbound requests from the web server