Resilient Malware Strain Targets WordPress Websites via Ethereum Infrastructure
A highly resilient and self-healing malware strain, dubbed 'SC,' has been discovered by security firm Sucuri. This strain targets WordPress websites and utilizes Ethereum infrastructure for command-and-control.
The SC malware can resurrect itself with the help of a network of redundant copies, making it extremely difficult to remove. According to Sucuri, the payload was found in at least eight different locations simultaneously, indicating that there is no single point of failure.
The malware functions as some sort of self-healing system, and its malicious payload is present in WordPress plugins, themes, the database, and supported servers. What's notable is that it contains a list of roughly 20 public Ethereum RPC gateways, making it highly resilient against blocks.
If one gateway gets blocked, other Ethereum RPC providers will be used as alternative options, allowing the attackers to remain undetected. The malware also has the capability to grab administrator session tokens and perform JavaScript injections into the site's front end, which could lead to malicious activities such as skimming payment information.