According to security firm Sucuri, there is a dangerously persistent WordPress malware strain that relies on Ethereum infrastructure for command-and-control.

It is able to resurrect itself with the help of a network of redundant copies.

Refusing to die

The so-called "SC" malware functions as some sort of self-healing system, according to a recent report shared by the firm.

WordPress plugins, themes, the database, as well as supported servers contain copies of its malicious payload.

Sucuri said the payload was found in at least eight different locations simultaneously. The fact that there is no single point of failure makes this malware extremely powerful and the task of removing it way more arduous.

A traditional command-and-control server can be blocked. However, SC contains a list of roughly 20 public Ethereum RPC gateways.

In this case, legitimate blockchain infrastructure, which makes it possible for applications, wallets, and other software to interact with the network, is being used for malicious purposes.

If one gateway gets blocked, other Ethereum RPC providers will be used as alternative options. This makes the attackers way more resilient.

The fingerprinting of compromised websites involves collecting URLs and hostnames, WordPress version, installed plugin versions, and other information. What is notable is that this dangerous malware is also capable of grabbing administrator session tokens.

The attacker can then perform JavaScript injections into the site's front end. This, for instance, could be done to skim payment information during checkout on e-commerce websites because of this malware.

SC can also deactivate security software and even maintain administrator-level access inside WordPress.

Of course, the process of removing the infection is extremely challenging. If one sufficiently capable piece of the mesh survives, the malware may simply build itself again.