Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / News / The WordPress backdoor that rebuilds itself. Deleting the files is not a cleanup
Every agency has had the call: the site was cleaned last week and the malware is back. Sucuri published a breakdown on September 30 of a family it calls SC — named after the `SC_` markers it leaves in injected code — and it explains that call better than anything we’ve read this year. The payload keeps itself in eight places at once, and every one of them can rebuild all the others. This is the scenario a maintenance retainer that covers malware cleanup and re-scanning is built around, because a one-off clean here genuinely does not hold.
Per Sucuri’s analysis, the infection lives in:
Delete the plugin, the drop-in rewrites it. Delete the drop-in, the theme rewrites it. Wipe every file on disk and the next page load pulls the payload back out of the database or out of a System V shared-memory segment. Cron hooks with randomised names redeploy it even on a site with no visitors.
Two of those persistence points are why “I removed the bad files” keeps failing:
Instead of one hardcoded server, SC carries a list of roughly twenty public Ethereum RPC gateways and reads its instructions from smart contracts. Block one gateway and nineteen still answer, and there is no domain to sinkhole.
What it does with those instructions is the commercial part: it fingerprints the site (URL, host, WordPress and plugin versions, active theme, mu-plugin list, admin session tokens), creates a hidden administrator with valid auth cookies, hides itself from the plugin list and update transients, deactivates security plugins, and accepts front-end JavaScript — which on a WooCommerce site means card skimming at checkout.
Sucuri’s own removal order matters: neutralise the prepend directive first, then clear the database and shared-memory copies, then the cron hooks and the hidden admin, then the files in a single pass. Doing it in the other order takes the site down or leaves a seed behind. And if files reappear after a clean, that is not reinfection — it is a persistence point you missed, or an entry vector still open.
If you’re on one of our maintenance plans, these checks are part of the routine scan on your sites, and anything found is cleaned and written up in your next monthly maintenance report. There’s nothing for you to do here. If you’re not on a plan, this is the specific problem one solves: a cleanup is only finished when someone goes back a week later to confirm nothing grew back, and that second visit is usually the one nobody is paying for.
Source: Sucuri