
Sucuri Finds Self-Healing WordPress Malware Powered by Ethereum RPC
- —SC malware relies on about 20 public Ethereum RPC gateways instead of a single C2 server
- —Payload copies were found in at least 8 locations, including plugins, themes, database and servers
- —SC fingerprints sites by collecting WordPress and plugin versions and admin session tokens
- —The malware disables security software and injects JavaScript to skim payment data
Why it matters: The attack shows how legitimate blockchain infrastructure can be abused for resilient cyber campaigns, complicating website defense and the reputation of public RPC endpoints.
Source: U.Today