Sophisticated Self-Healing WordPress Backdoor Uncovered Alongside Active wpForo Flaw Exploitation

by Dimitri Dimitrov Published on October 1, 2026
Editorial Standards ▾

☆ Editorial Standards

All news content is produced by qualified journalists and analysts under a published editorial code requiring accuracy, source verification, and editorial review prior to publication.

Advertisers and commercial partners have no influence over news coverage.


News editorial policy · Contact us
✓ Fact-Checked ▾

✓ Fact-Checked

Every article undergoes senior editorial review.

Regulatory and legal reporting is cross-referenced against primary sources including official government and regulatory authority records.

Corrections are issued transparently with a visible update notice.


News fact-check policy
⊘ Independence ▾

⊘ Independence

Gamblers Connect is a B2B iGaming media platform.

Editorial decisions, including what to cover, how to cover it, and what to publish, are made independently by our newsroom.

Commercial partners may purchase publication frequency but cannot influence editorial tone, angle, or content.


News independence policy
↗ Commercial Disclosure ▾

↗ Commercial Disclosure

Gamblers Connect is a B2B media platform. We generate revenue through subscriptions, B2B referral partnerships, directory listings, advertising, and media services.

Gamblers Connect is not a licensed gambling operator, affiliate, or player acquisition channel in any jurisdiction.

We do not earn revenue from player activity, wagers, or deposits.


News commercial disclosure · Contact us
Close-up of a laptop screen displaying the WordPress website builder interface.
Key Takeaways
⏱ 2 min read
1
Self-Healing Architecture — The SC backdoor replicates its payload across eight distinct file, database, and shared-memory components, making standard manual cleanup ineffective
2
Blockchain C2 Communication — The malware hides its command channel by leveraging the Ethereum blockchain to retrieve payloads and coordinate reinfection loops
3
Complex Initial Access — While the exact delivery vector for the SC malware remains undetermined, common entry points include plugin vulnerabilities, weak credentials, and insecure file uploads
4
Active wpForo Exploitation — CVE-2026-1581, a high-severity SQL injection flaw in the wpForo Forum plugin up to version 2.4.14, is currently facing active exploitation in the wild

Security researchers have uncovered a highly complex WordPress compromise involving a self-healing, blockchain-controlled backdoor codenamed “SC”. Discovered by Sucuri, the malware deploys multiple interconnected persistence mechanisms across a server to ensure the payload continually regenerates if removed.

An Eight-Component Self-Healing Mesh

According to Sucuri, the backdoor uses a substitution cipher to decode its functions and spreads identical copies of its payload across at least eight distinct locations, including files, the database, and shared memory. Security researcher Gabriel Barbosa noted that the system creates a circular loop with no single point of failure:

  • .user.ini: Sets auto_prepend_file to execute a loader prior to every PHP request in the directory tree.
  • wp-content/c1b12371.php: A loader file designed to include a hidden dot-prefixed file if present in the same location.
  • wp-content/.c1b12371.php: A hidden first-stage loader that locates a fake plugin and rebuilds it inside mu-plugins using local files, cache stubs, or a ZIP restore bundle.
  • wp-content/db.php: Loaded during bootstrap, carrying the full backdoor payload in a compressed, Base64-encoded format to re-deploy missing plugins.
  • wp-content/advanced-cache.php: Loaded prior to ordinary plugins when caching is enabled, rebuilding the plugin from five independent sources including shared memory and the database.
  • wp-content/themes/khorshidi/functions.php: A theme-resident twin of the backdoor payload that rewrites the plugin if it is missing.
  • wp-content/mu-plugins/hyper-engine-kit.php: The core malware installed as both a must-use and normal plugin.
  • wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php: A redundant duplicate of the backdoor payload.

Furthermore, on servers supporting System V shared memory, the payload resides in a RAM segment identified by a fixed numeric key, allowing it to survive file and database cleanups. The malware also registers cron hooks to automate redeployment and communicates with its command-and-control (C2) server via the Ethereum blockchain to fetch additional payloads, inject JavaScript skimmers, create hidden administrator accounts, and execute arbitrary PHP code.

Active Exploitation of wpForo Forum Plugin Flaw

Concurrent with the disclosure of the SC malware, telemetry data from Previdian has revealed active exploitation of a high-severity unauthenticated SQL injection vulnerability in the wpForo Forum WordPress plugin. Tracked as CVE-2026-1581 with a CVSS score of 7.5, the flaw affects all versions up to and including 2.4.14. Fewer than 20 exploitation attempts have been tracked since July 3, 2026, originating from IP addresses in Bulgaria, Switzerland, France, the U.S., and Yemen.

Dimitri Dimitrov

Dimitri is an iGaming expert with nearly a decade of experience and a knack for crafting content that speaks directly to the iGaming crowd. He understands affiliate marketing, player psychology, and search algorithms, which enables him to write engaging, data-driven articles.

Sources
1 source verified before publication. This news is an official press release that traces directly to official documents by The Hacker News. How we verify sources →
1
The Hacker News
· Official Body Primary
https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html ↗
✓ Gamblers Connect only publishes verified and official news from reputable media outlets. Read our full editorial standards →
Mentioned in this Article