WordPress Backdoor SC Self-Heals Using Files, Database, and Shared Memory
Researchers identify persistent foothold mechanism that rebuilds payloads after cleanup

Key Takeaways
- Sucuri researchers have identified a WordPress backdoor codenamed SC that uses multiple persistence mechanisms to self-replicate after cleanup.
- The malware leverages injected files, database entries, and shared memory segments as part of a "self-healing mesh" strategy.
- Threat actors embedded "SC_" markers in injected content to facilitate reconstruction of the malicious payload.
Related Security News
International Law Enforcement Disrupts KillSec Ransomware Operation, Alleged Mastermind Identified as Teenager
Law enforcement agencies from multiple countries have collaborated to disrupt the KillSec ransomware operation. According to reports, the alleged mastermind is a 16-year-old individual. The operation is accused of targeting roughly 500 victims worldwide over the past two years. The disruption marks a significant action against a ransomware group that has been active in extorting organizations globally.



