HackerFeeds

CyberSecurity News

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News
· October 1, 2026

AI summary

Cybersecurity researchers have discovered a WordPress compromise where attackers used multiple methods to maintain access to the site. The backdoor, codenamed SC, uses various persistence mechanisms to rebuild itself after being cleaned up. These mechanisms involve files, database, and shared memory, allowing the final payload to return without requiring reinfection. The malware has been described as a self-healing mesh by Sucuri. This complex setup enables the backdoor to persist on the compromised site. The SC backdoor is characterized by "SC_" markers in the injected content.

Read the full article at The Hacker Newsthehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.