WordPress backdoor can rebuild itself – why DIY cleanup fails

Why the backdoor keeps returning
Imagine you run a small bakery that also sells pastries online. One day you notice strange orders and suspect your website has been compromised. You delete the suspicious plugin, clean the files, and think the problem is solved. A few days later the same malicious code reappears, seemingly out of nowhere.
That is exactly what security researchers at Sucuri have observed with a new WordPress malware. The code is not a single file you can delete; it lives in eight different places on the site – in files, the database, and even in server memory. Each piece can rebuild the others, so removing one “copy” does not break the infection.
For a business owner who is not a tech expert, the takeaway is simple: cleaning a WordPress hack yourself is risky because the malware can resurrect itself. The safest route is to keep clean, recent backups, use continuous security monitoring, and call in professionals when you suspect a breach.
The eight ways the backdoor hides and rebuilds itself
Below is a plain‑language walk‑through of the eight persistence mechanisms. Think of them as a set of secret “spare parts” that the malware stores in different drawers; if you empty one drawer, another still holds the parts needed to rebuild the whole machine.
-
Auto‑prepend file (
.user.ini) – This tiny configuration file tells PHP to run a hidden loader before every request. Deleting the loader does not remove the instruction, so the loader is called again on the next page view. -
Loader script (
c1b12371.php) – A regular‑looking PHP file that looks for a hidden “dot‑prefixed” file in the same folder. If it finds it, it runs the hidden code. -
Hidden dot‑prefixed file (
.c1b12371.php) – This invisible file is the first stage of the backdoor. It can recreate a fake plugin in the must‑use plugins folder (a special folder that WordPress loads automatically and cannot be deactivated from the admin panel) by pulling code from three sources: an existing copy, an encoded stub hidden in the cache, or a ZIP file with a random name. -
Database payload (
db.php) – The entire malicious code is stored in the WordPress database, compressed and encoded. When the file system copy disappears, the script reads the database, decodes the payload, and writes the plugin back to disk. -
Advanced cache drop‑in (
advanced-cache.php) – WordPress loads this file before normal plugins when caching is enabled. It can rebuild the malware from five independent sources, including a shared‑memory segment (a piece of RAM that survives file deletion). -
Theme‑resident twin (
functions.phpin a theme folder) – A copy of the same backdoor lives inside the active theme’s functions file. If the plugin is missing, this file rewrites it. -
Must‑use plugin (
hyper-engine-kit.php) – The real malicious code is installed as a must‑use plugin, which WordPress loads automatically and cannot be deactivated from the admin panel. -
Regular plugin copy (
hyper-engine-kit.phpin the plugins folder) – A duplicate of the same code sits in the normal plugins directory, providing another fallback.
Because each component can pull the others from the database, the file system, or even shared memory, the infection behaves like a self‑healing mesh. Removing any single piece does not stop the cycle; the next page load simply restores the missing parts.
Why DIY cleanup often fails
Most small‑business owners try to fix a hack by:
- Deleting the suspicious plugin from the admin dashboard.
- Removing a few files via FTP.
- Running a one‑time scan with a free tool.
With this backdoor, those steps are insufficient because:
- Hidden files are invisible – Files that start with a dot (
.c1b12371.php) do not show up in typical FTP listings unless you enable “show hidden files.” - Database storage is overlooked – The malicious code lives inside the WordPress database, which most cleanup guides do not address.
- Shared memory survives disk cleanup – On servers that support System V shared memory, the payload lives in RAM, so even a fresh reinstall of WordPress does not erase it.
- Multiple entry points – The backdoor can rebuild itself from any surviving copy, meaning you would have to locate and delete all eight components simultaneously – a task that requires deep knowledge of WordPress internals.
In short, a “quick fix” can give a false sense of security while the malware silently waits to re‑activate.
The practical lesson for your business
-
Keep clean, recent backups – A backup taken before the infection is your safety net. Store it offline or in a separate cloud bucket so that even if the site is compromised, you can restore a clean version quickly.
-
Use continuous security monitoring – Real‑time malware scanning can detect unusual changes (new files, altered database entries, unknown cron jobs) the moment they happen, giving you a chance to intervene before the backdoor rebuilds.
-
Treat a suspected breach as a professional incident – If you notice strange admin users, unexpected redirects, or a drop in traffic, call a security specialist. Trying to “fix it yourself” can unintentionally trigger the malware’s self‑healing routine.
-
Limit access and harden login security – Strong passwords, two‑factor authentication (an extra security step, like a code sent to your phone), and limiting login attempts reduce the chance that attackers gain the initial foothold.
-
Regularly update WordPress, themes, and plugins – Many infections start with known vulnerabilities. Keeping everything up‑to‑date removes a large attack surface.
Want more tips? Check out our guide on WordPress security best practices.
FAQ
Q: I’m not a tech expert. Can I safely remove a WordPress hack myself?
A: Simple hacks that live in a single file can sometimes be removed by an experienced admin, but sophisticated malware like this backdoor spreads across many hidden locations. For most small‑business owners, the safest approach is to let a security professional handle the cleanup.
Q: How often should I back up my website?
A: At least once a week, and more frequently if you add new products or content daily. Automated daily backups give you the most recent clean copy to restore from.
Q: What does “continuous monitoring” mean for my site?
A: It means a service that constantly scans your files, database, and server behavior for signs of infection or unauthorized changes, and alerts you (or takes automatic action) the moment something suspicious is detected.
Q: How can I tell if my site is infected?
A: Look for unexpected admin users, sudden redirects, unknown files (especially hidden ones that start with a dot), or a drop in site performance. If you spot any of these, run a scan and consider a professional review.
Keep your site safe with IT Move NL
Dealing with a hidden WordPress backdoor is stressful, but you don’t have to face it alone. Our Security & Protection service combines real‑time malware scanning, automated backup‑restore, and expert incident response. We monitor your site 24/7, keep clean backups ready, and step in immediately if a breach is suspected.
Ready for peace of mind?
Just drop us a line – we’re happy to take a look and help you keep your online business running smoothly.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch

