WordPress Malware that relies on Ethereum infrastructure is difficult to remove
U.Today
2h ago
Ai Focus
According to security company Sucuri, a type of WordPress malware that relies on Ethereum infrastructure for command and control continues to exist and is capable of self-recovery through redundant replica networks. This malware collects information from infected websites, steals administrator session tokens, and can inject JavaScript into the website frontend.
Helpful
No.Help

According to security company Sucuri, there is a dangerous and persistent variant of WordPress malware that relies on Ethereum infrastructure for command and control.

This malware is capable of "reviving" itself by leveraging a network of redundant copies.

Refuse to disappear

In a recent report, Sucuri stated that this malware, named “SC”, is to some extent like a self-repairing system.

The WordPress plugin, themes, databases, and supported servers all contain copies of its malicious payload.

Sucuri indicates that they discovered this payload at at least eight different locations simultaneously. Since there is no single point of failure, this malware is extremely powerful, and the task of removal is also much more difficult.

Traditional command and control servers can be blocked. However, SC contains a list of about 20 public Ethereum RPC gateways.

In this case, the legitimate blockchain infrastructure, which is originally used to enable applications, wallets, and other software to interact with blockchain networks, is being utilized for malicious purposes.

If a certain gateway is blocked, other Ethereum RPC providers will be used as alternative options. This makes attackers more resilient.

Fingerprint recognition of infected websites includes collecting website addresses and hostnames, WordPress versions, installed plugin versions, and other information. It is worth noting that this dangerous malware is also capable of obtaining administrator session tokens.

Subsequently, attackers can inject JavaScript into the website's front end. For example, on an e-commerce website during the checkout process, this could be used to steal payment information, as the malware has such capabilities.

SC It is also possible to disable security software, and even maintain administrator-level access rights within WordPress.

Of course, the process of removing infections is extremely difficult. If there are some sufficiently powerful components in the network that survive, the malware may simply rebuild itself.

Tip
$0
Like
0
Save
0
Views 19
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
ESCO Completes the Acquisition of Megger Group Limited
ESCO Technologies Inc announces the completion of the acquisition of Megger Group Limited under TBG AG. The company stated that Megger will be integrated into Utility Solutions Group, and plans to announce the financial guidance and outlook for the fiscal year 2027, including the impact of this acquisition, when releasing the results for the fourth quarter of the fiscal year 2026 in November.
GlobeNewswire
·2026-10-02 04:26:30
10
IGEL to Host Now & Next ® Summit in Dubai, Focusing on Current and Future Workspace and Terminal Security
IGEL announces that it will host a sub-event of the Now & Next ® Summit on October 21, 2026, at the Dubai Knowledge Park. The event will focus on discussions surrounding endpoint security, resilience, and digital workspaces. Microsoft, Omnissa, and Lenovo will participate in providing support. The company stated that this event aims to bring together customers, partners, and industry experts to discuss the security challenges faced by enterprises in the Middle East amidst the backdrop of digital transformation.
PR Newswire
·2026-10-02 04:06:52
12
Singapore uses Nobel Prize-winning algorithm to help young civil servants find partners
The Singapore Government Technology Agency has launched a pilot project named FirstDate, aimed at single public servants aged 21 to 35. The service provides each participant with a potential match and requires them to decide within 72 hours whether to establish contact. This initiative uses a stable matching algorithm called Gale-Shapley in response to the declining trend of late marriage and birth rates in Singapore.
Fortune
·2026-10-02 03:57:13
14
Google believes that the starships of SpaceX need to be launched 1,600 times before a space data center can even get off the ground.
Google's orbital computing power satellite was launched today aboard the SpaceX rocket from California. This marks the first time that the tech giant has sent advanced chips into space. Google has also released a peer-reviewed white paper on orbital data centers, stating that to support the expansion of orbital data centers at a sufficiently low cost, it may be necessary to complete approximately 1,800 launches over the next decade.
TechCrunch
·2026-10-02 03:36:14
18
More than 50,000 Europeans call on the EU to relax restrictions on stablecoin rewards during the MiCA review
According to Stand With Crypto EU, over 50,000 Europeans are urging the European Commission to relax restrictions on stablecoin incentives during the MiCA review, allowing regulated stablecoin providers to offer cashbacks, loyalty benefits, and fee reductions as incentives. The organization also stated that more than 126,000 people have signed a petition, while the European Central Bank system is calling for further tightening of relevant regulations.
Cointelegraph
·2026-10-02 03:17:18
17
View More