Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

Self-Healing WordPress Backdoor SC Survives Cleanup: What Canadian Site Owners Must Do

What Happened

Sucuri researchers found a WordPress backdoor named SC, after the SC_ markers in its injected content. It rebuilds itself after cleanup. The malware keeps copies in eight places: a .user.ini file with an auto_prepend_file setting, two loader files in wp-content, a db.php drop-in carrying the compressed payload, an advanced-cache.php drop-in, a theme functions.php, a must-use plugin, and a plugin named hyper-engine-kit. System V shared memory holds more copies, so deleting files alone fails.

SC hides from admin screens and update checks, creates hidden administrator accounts, runs arbitrary PHP, and injects JavaScript aimed at visitors. It uses the Ethereum blockchain for command and control, so blocking one domain does not cut it off. Researchers do not know how it gets in. The Hacker News has the full list.

Why This Matters for Canadian Organizations

WordPress runs the sites of Canadian small businesses, municipalities, clinics, nonprofits, and law firms. Many have no dedicated security staff. They clean a site by deleting a suspicious plugin, see the problem disappear, and move on. With SC, the drop-in rewrites the plugin and the loop restarts.

Visitor-targeting JavaScript turns your site against your own customers. If the site collects forms, bookings, or payments, a compromise exposes personal information and brings PIPEDA breach assessment duties. Quebec organizations answer to Law 25 as well. No Canadian victims have been reported, but the delivery method is unknown, so any unpatched site is a candidate.

What to Do

Check for each of the eight locations and remove every copy in one pass. Restart PHP and the web server so shared memory segments clear. Restoring from a backup made before the infection is safer than cleaning in place. Review all administrator accounts and delete unknown ones. Rotate database, hosting, and WordPress credentials and regenerate the security salts. Update core, plugins, and themes, then remove anything unused. Add file integrity monitoring so a rewritten drop-in triggers an alert.

Read more in our TechTalk section and see today’s roundup in News.

Enjoy this article? Don’t forget to share.