Security company Sucuri has reported the discovery of a persistent malware variant targeting WordPress sites, which leverages the Ethereum blockchain’s infrastructure as part of its command-a
Security company Sucuri has reported the discovery of a persistent malware variant targeting WordPress sites, which leverages the Ethereum blockchain’s infrastructure as part of its command-and-control operations.
Ethereum-powered command and control
This malware, referred to as “SC” by Sucuri, has been described as a “self-healing” threat. Instead of relying on a traditional centralized command-and-control server, the malware utilizes a list of roughly 20 public Ethereum Remote Procedure Call (RPC) gateways to receive instructions. By distributing control mechanisms across several decentralized gateways, rather than a single server, attackers ensure there is no single point of failure.
Should a gateway be blocked or removed, the malware seamlessly switches to another available Ethereum RPC provider. This use of legitimate blockchain infrastructure, which typically allows applications, wallets, and services to access the Ethereum network, gives attackers enhanced resilience and flexibility.
Mini dictionary: Ethereum RPC Gateway, a public interface that allows software to access and interact with blockchain data on the Ethereum network without running a full node.
Traditional C2 Method
“SC” Malware Approach
Single central server used for commands
Roughly 20 public Ethereum RPC gateways leveraged
Easier to block by defenders
No single point of failure, switching between gateways
Not blockchain-based
Uses legitimate blockchain infrastructure
Persistence and infection method
SC malware maintains resilience by hiding copies of its malicious payload in multiple places, including WordPress plugins, themes, the database, and the server environment. Sucuri identified the malware simultaneously in at least eight separate locations across infected systems. This redundancy allows the malware to regenerate itself even after partial removal attempts, making full eradication significantly more complex for administrators.
Sucuri highlighted the danger of the malware’s design. The distributed storage of its components and the use of decentralized infrastructure mean that standard remediation efforts are often insufficient if even a single malware variant survives.
Capabilities and risks
The SC malware collects details from compromised websites, including URLs, hostnames, WordPress version information, and plugin versions. Notably, it can also steal administrator session tokens, giving attackers prolonged privileged access.
Attackers may use their access to inject JavaScript into a site’s front end. This enables various malicious actions, such as skimming payment card details from e-commerce transactions during user checkout processes.
SC can also deactivate a range of security software and maintain administrator-level access within WordPress, making disinfection attempts even more difficult.
Given this malware’s architectural resilience, Sucuri stressed that the recovery process for affected websites is challenging. Even if a lone undetected instance of the payload remains, it can quickly restore the malware across the system.
The post WordPress malware uses Ethereum RPC for self-healing attacks, Sucuri warns appeared first on COINTURK NEWS.