Security firm Sucuri has uncovered a sophisticated malware targeting WordPress sites, which uses the Ethereum network for command and control communications. Dubbed “SC,” this malware is particularly challenging to eradicate due to its ability to regenerate through multiple backup copies.
Malware Embeds in Multiple System Layers
According to Sucuri’s findings, the malware penetrates various layers within WordPress ecosystems, including plugins, themes, databases, and supporting servers. The firm has identified malicious components dispersed across at least eight different locations simultaneously, amplifying the attack’s impact by eliminating the risk of a single point of failure.
This architecture complicates efforts to remove the malware using conventional security tools, which typically focus on individual files or servers. Even if one robust element remains untouched, the malware can re-establish itself across the system.
Succuri emphasizes that SC is present at a minimum of eight points, making the removal of a single component insufficient to end the infection.
Exploitation of Ethereum RPC Gateways
The report highlights that traditional command-and-control servers can be blocked, but SC maintains a list of around 20 public Ethereum RPC gateways. These gateways are known as technical access points that allow applications and wallets to communicate with the blockchain network.
When one gateway is blocked, attackers can pivot to other Ethereum RPC providers, leveraging legitimate blockchain infrastructure to bolster the resilience of their attacks.
While a traditional command-and-control server might be shut down, SC’s ability to switch between numerous public Ethereum RPC providers adds an extra layer of resilience for the attackers.
Admin Access and Payment Data at Risk
Sucuri notes that compromised sites undergo detailed fingerprinting processes, collecting URLs, hostnames, WordPress versions, installed plugin versions, and other technical data. Alarmingly, the malware can also capture admin session tokens.
With this access, attackers can inject JavaScript code into the site’s frontend, posing significant risks such as collecting user information during payment processes on e-commerce platforms. The malware can disable security tools and maintain admin-level access within WordPress as well.
Complexity of the Cleanup Process
Sucuri stresses the extraordinary difficulty in eradicating the infection. The issue stems from the malware’s operation through interconnected multiple copies rather than isolated files or services. Incomplete cleanup attempts may lead to the malware’s rapid re-emergence.
The firm’s assessment points to more resilient attacks targeting the WordPress ecosystem and its supporting infrastructure. The misuse of widely adopted technical services like Ethereum complicates defensive strategies, underscoring the complexity of contemporary cybersecurity challenges.



