MobbleOpen in Mobble ⇢
Business · Cryptocurrency · published 2026-10-01 · via Bitcoin Haber

Sophisticated Malware Exploits Ethereum Network to Compromise WordPress Websites

Image via Bitcoin Haber
Image via Bitcoin Haber

Security researchers have identified a complex malware strain called SC that targets WordPress sites by leveraging the Ethereum network for command-and-control operations, making it exceptionally difficult to remove. The malware embeds itself across multiple system layers including plugins, themes, and databases simultaneously, with the ability to regenerate if even one component remains infected. Attackers use approximately 20 public Ethereum RPC gateways to maintain resilience, allowing them to switch between access points if individual channels are blocked.

Expanded Detail

The SC malware represents a significant evolution in WordPress attack methodology. Rather than relying on traditional centralized command servers vulnerable to takedown, the attackers exploit the decentralized nature of blockchain infrastructure by distributing control across multiple Ethereum RPC endpoints. This approach transforms legitimate cryptocurrency network access points into unwitting facilitators of cybercrime, forcing defenders to balance security responses against disrupting valid blockchain operations.

The infection's resilience stems from its distributed architecture across eight or more system components—spanning database records, theme files, plugin code, and server configurations simultaneously. This redundancy means attackers can afford to lose several infection vectors while maintaining persistence, rendering standard removal tools inadequate and requiring comprehensive forensic cleanup across interconnected infrastructure layers.

Context

This threat could significantly impact WordPress-dependent businesses, particularly e-commerce platforms handling payment data and smaller organizations with limited security resources. The misuse of public blockchain infrastructure to facilitate attacks may prompt discussions about RPC gateway security practices and liability. Website owners could face increased remediation costs and operational downtime, while the incident underscores broader vulnerabilities in widely-used content management systems that balance accessibility with security hardening.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Bitcoin Haber →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Persistent Malware Targets WordPress Sites via Ethereum Network.” Browse more stories.