WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Researchers have detailed a WordPress compromise deploying multiple persistence mechanisms — files, database, and shared memory — so the payload keeps returning without reinfection. Sucuri describes the ‘SC’-marked malware as a ‘self-healing mesh’ that rebuilds itself after cleanup.

Edward Kiledjian @ekiledjian