According to security company Sucuri, there is a dangerous and persistent variant of WordPress malware that relies on Ethereum infrastructure for command and control.
This malware is capable of "reviving" itself by leveraging a network of redundant copies.
Refuse to disappear
In a recent report, Sucuri stated that this malware, named “SC”, is to some extent like a self-repairing system.
The WordPress plugin, themes, databases, and supported servers all contain copies of its malicious payload.
Sucuri indicates that they discovered this payload at at least eight different locations simultaneously. Since there is no single point of failure, this malware is extremely powerful, and the task of removal is also much more difficult.
Traditional command and control servers can be blocked. However, SC contains a list of about 20 public Ethereum RPC gateways.
In this case, the legitimate blockchain infrastructure, which is originally used to enable applications, wallets, and other software to interact with blockchain networks, is being utilized for malicious purposes.
If a certain gateway is blocked, other Ethereum RPC providers will be used as alternative options. This makes attackers more resilient.
Fingerprint recognition of infected websites includes collecting website addresses and hostnames, WordPress versions, installed plugin versions, and other information. It is worth noting that this dangerous malware is also capable of obtaining administrator session tokens.
Subsequently, attackers can inject JavaScript into the website's front end. For example, on an e-commerce website during the checkout process, this could be used to steal payment information, as the malware has such capabilities.
SC It is also possible to disable security software, and even maintain administrator-level access rights within WordPress.
Of course, the process of removing infections is extremely difficult. If there are some sufficiently powerful components in the network that survive, the malware may simply rebuild itself.












