Find notable cyber news and cases, enriched with sources, timelines, and signals.

SC WordPress backdoor with multi-location persistence and Ethereum C2

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The SC backdoor on WordPress sites now uses multi-location persistence and Ethereum blockchain C2, letting infected sites rebuild themselves after cleanup and keep serving malicious code. It can create hidden admin accounts, fetch payloads, and inject JavaScript into visitors. The design turns a single compromise into a resilient foothold that is difficult to remove.

Related Happenings

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...

SocGholish malware downloader hijacking WordPress sites

Malware Activity
H score57 First: 18.06.2026 16:25 Last: 18.06.2026 16:25 Sources 1

About this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...

WordPress malware hides C2 data in Steam Community comments

Malware Activity
H score16 First: 01.06.2026 20:04 Last: 01.06.2026 20:04 Sources 1

About this happening: A WordPress malware operation has been uncovered on approximately 1,980 websites, raising the risk of hidden command-and-control (C2) traffic and persistent page injec...

WordPress malware campaign using Steam profile C2 concealment

Campaign
H score37 First: 01.06.2026 20:04 Last: 01.06.2026 20:04 Sources 1

About this happening: A WordPress malware campaign has infected about 1,980 websites since July 2025, and it hides command-and-control (C2) data in Steam Community profile comments...

EssentialPlugin package hit by network compromise

Incident
H score25 First: 15.04.2026 23:33 Last: 15.04.2026 23:33 Sources 1

About this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...

Timeline

  1. 01.10.2026 17:37 2 articles · 1h ago

    Researchers disclose SC WordPress backdoor with self-healing persistence

    Initial Disclosure

    Security researchers disclosed the SC WordPress backdoor, a self-healing mesh that spreads across .user.ini, plugin, theme, database, and shared-memory locations so deleted copies can be rebuilt. The malware hides from admin views, uses Ethereum blockchain as a C2 channel, can create a hidden administrator account, fetch and inject arbitrary JavaScript, run PHP code, and deactivate or delete plugins. Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin was also observed, with fewer than 20 attempts since July 3, 2026.

    Show sources