Menu

Search

  |   Digital Currency

Menu

  |   Digital Currency

Search

Google Add as a preferred source on Google

WordPress Malware Uses Ethereum to Evade Removal

WordPress Malware Uses Ethereum to Evade Removal. Source: EconoTimes

Security researchers have uncovered a persistent WordPress malware strain that uses Ethereum infrastructure for command-and-control communications, making infected websites unusually difficult to clean.

According to cybersecurity firm Sucuri, the malware, known as “SC,” operates as a self-healing system capable of rebuilding itself even after administrators remove parts of the infection. Copies of the malicious payload are distributed across WordPress plugins, themes, databases and server environments.

Sucuri researchers discovered the payload in at least eight locations at the same time. This redundancy eliminates a single point of failure, meaning removing one infected component may not be enough to secure a compromised WordPress website.

The malware also avoids relying on a conventional command-and-control server that security teams could identify and block. Instead, SC reportedly contains a list of roughly 20 public Ethereum RPC gateways.

Ethereum RPC infrastructure normally allows wallets, applications and other software to communicate with the Ethereum blockchain. SC exploits these legitimate services for malicious communications. If one RPC provider becomes inaccessible, the malware can switch to another gateway, improving the attackers’ resilience against attempts to disrupt their operations.

The threat also gathers detailed information about compromised websites, including URLs, hostnames, WordPress versions and installed plugin versions. More seriously, SC can steal administrator session tokens, potentially allowing attackers to retain privileged access.

Attackers can then inject malicious JavaScript into a website’s front end. On e-commerce sites, such injections could potentially be used to capture payment information entered by customers during checkout.

Sucuri also found that the WordPress malware can disable security software and maintain administrator-level access, further complicating remediation efforts.

The malware’s distributed design means website owners may need to identify and eliminate every surviving component. If even one functional copy remains hidden within the compromised environment, SC may be capable of reconstructing the infection and restoring malicious access.

The discovery highlights how cybercriminals can abuse decentralized blockchain infrastructure such as Ethereum RPC gateways to make malware operations harder to disrupt.

  • Market Data
Close

Welcome to EconoTimes

Sign up for daily updates for the most important
stories unfolding in the global economy.