WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Researchers have detailed a WordPress compromise deploying multiple persistence mechanisms — files, database, and shared memory — so the payload keeps returning without reinfection. Sucuri describes the ‘SC’-marked malware as a ‘self-healing mesh’ that rebuilds itself after cleanup.