SC WordPress backdoor with multi-location persistence and Ethereum C2
Malware Activity
Summary
Hide ▲
Show ▼
The SC backdoor on WordPress sites now uses multi-location persistence and Ethereum blockchain C2, letting infected sites rebuild themselves after cleanup and keep serving malicious code. It can create hidden admin accounts, fetch payloads, and inject JavaScript into visitors. The design turns a single compromise into a resilient foothold that is difficult to remove.
Related Happenings
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
SocGholish malware downloader hijacking WordPress sites
Malware Activity
H score57
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
About this happening:
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
SocGholish malware downloader hijacking WordPress sites
Malware ActivityAbout this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
WordPress malware hides C2 data in Steam Community comments
Malware Activity
H score16
First: 01.06.2026 20:04
Last: 01.06.2026 20:04
Sources 1
About this happening:
A WordPress malware operation has been uncovered on approximately 1,980 websites, raising the risk of hidden command-and-control (C2) traffic and persistent page injec...
WordPress malware hides C2 data in Steam Community comments
Malware ActivityAbout this happening: A WordPress malware operation has been uncovered on approximately 1,980 websites, raising the risk of hidden command-and-control (C2) traffic and persistent page injec...
WordPress malware campaign using Steam profile C2 concealment
Campaign
H score37
First: 01.06.2026 20:04
Last: 01.06.2026 20:04
Sources 1
About this happening:
A WordPress malware campaign has infected about 1,980 websites since July 2025, and it hides command-and-control (C2) data in Steam Community profile comments...
WordPress malware campaign using Steam profile C2 concealment
CampaignAbout this happening: A WordPress malware campaign has infected about 1,980 websites since July 2025, and it hides command-and-control (C2) data in Steam Community profile comments...
EssentialPlugin package hit by network compromise
Incident
H score25
First: 15.04.2026 23:33
Last: 15.04.2026 23:33
Sources 1
About this happening:
The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
EssentialPlugin package hit by network compromise
IncidentAbout this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
Timeline
-
01.10.2026 17:37 2 articles · 1h ago
Researchers disclose SC WordPress backdoor with self-healing persistence
Initial DisclosureSecurity researchers disclosed the SC WordPress backdoor, a self-healing mesh that spreads across .user.ini, plugin, theme, database, and shared-memory locations so deleted copies can be rebuilt. The malware hides from admin views, uses Ethereum blockchain as a C2 channel, can create a hidden administrator account, fetch and inject arbitrary JavaScript, run PHP code, and deactivate or delete plugins. Active exploitation of CVE-2026-1581 in the wpForo Forum WordPress plugin was also observed, with fewer than 20 attempts since July 3, 2026.
Show sources
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory — thehackernews.com — 01.10.2026 17:37
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory — thehackernews.com — 01.10.2026 17:37