WordPress Malware that relies on Ethereum infrastructure is difficult to remove
U.Today
1h ago
Ai Focus
According to security company Sucuri, a type of WordPress malware that relies on Ethereum infrastructure for command and control continues to exist and is capable of self-recovery through redundant replica networks. This malware collects information from infected websites, steals administrator session tokens, and can inject JavaScript into the website frontend.
Helpful
No.Help

According to security company Sucuri, there is a dangerous and persistent variant of WordPress malware that relies on Ethereum infrastructure for command and control.

This malware is capable of "reviving" itself by leveraging a network of redundant copies.

Refuse to disappear

In a recent report, Sucuri stated that this malware, named “SC”, is to some extent like a self-repairing system.

The WordPress plugin, themes, databases, and supported servers all contain copies of its malicious payload.

Sucuri indicates that they discovered this payload at at least eight different locations simultaneously. Since there is no single point of failure, this malware is extremely powerful, and the task of removal is also much more difficult.

Traditional command and control servers can be blocked. However, SC contains a list of about 20 public Ethereum RPC gateways.

In this case, the legitimate blockchain infrastructure, which is originally used to enable applications, wallets, and other software to interact with blockchain networks, is being utilized for malicious purposes.

If a certain gateway is blocked, other Ethereum RPC providers will be used as alternative options. This makes attackers more resilient.

Fingerprint recognition of infected websites includes collecting website addresses and hostnames, WordPress versions, installed plugin versions, and other information. It is worth noting that this dangerous malware is also capable of obtaining administrator session tokens.

Subsequently, attackers can inject JavaScript into the website's front end. For example, on an e-commerce website during the checkout process, this could be used to steal payment information, as the malware has such capabilities.

SC It is also possible to disable security software, and even maintain administrator-level access rights within WordPress.

Of course, the process of removing infections is extremely difficult. If there are some sufficiently powerful components in the network that survive, the malware may simply rebuild itself.

Tip
$0
Like
0
Save
0
Views 13
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Google believes that the starships of SpaceX need to be launched 1,600 times before a space data center can even get off the ground.
Google's orbital computing power satellite was launched today aboard the SpaceX rocket from California. This marks the first time that the tech giant has sent advanced chips into space. Google has also released a peer-reviewed white paper on orbital data centers, stating that to support the expansion of orbital data centers at a sufficiently low cost, it may be necessary to complete approximately 1,800 launches over the next decade.
TechCrunch
·2026-10-02 03:36:14
7
More than 50,000 Europeans call on the EU to relax restrictions on stablecoin rewards during the MiCA review
According to Stand With Crypto EU, over 50,000 Europeans are urging the European Commission to relax restrictions on stablecoin incentives during the MiCA review, allowing regulated stablecoin providers to offer cashbacks, loyalty benefits, and fee reductions as incentives. The organization also stated that more than 126,000 people have signed a petition, while the European Central Bank system is calling for further tightening of relevant regulations.
Cointelegraph
·2026-10-02 03:17:18
11
Lowest Fee Bitcoin ATMs Announces the Launch of Over 400 ATM Units Across the United States
Lowest Fee Bitcoin ATMs Announces the Launch of Over 400 Cryptocurrencies in the United States ATM, Supporting the Purchase of Bitcoin, Ethereum, USDT, and USDC with Cash, Charging a Uniform 5% Fee, and Providing an Online Pre-registration Feature.
Decrypt
·2026-10-02 03:17:16
9
Citi raises its 12-month target price for Bitcoin to $113,000
Citi raised its 12-month target price for Bitcoin on Thursday from $82,000 to $113,000, stating that renewed attention to cryptocurrencies, improved market sentiment, and inflows of ETF funds will drive prices upward. The bank also raised its target price for Ethereum from $2,240 to $3,028.
Fortune
·2026-10-02 02:16:16
16
View More