Etherhiding in WordPress: How Hackers Hide C2 Servers Behind Smart Contracts
Traditionally, when a WordPress website is hacked, the malware communicates with a remote server operated by the attacker (called a Command-and-Control, or C2, server). Security firms can track that server's IP address, submit abuse requests to the host, and take down the command infrastructure.
In 2026, threat actors developed a resilient evolution: Etherhiding.
Instead of hardcoding a server IP or domain in your hacked WordPress files, the malware queries a decentralized smart contract on the Ethereum, Polygon, or Binance Smart Chain (BNB) blockchain. The smart contract returns the attacker's dynamic payload. Because public blockchains cannot be shut down or censored by hosting providers, the attacker's command channel is practically indestructible.
How Etherhiding Compromises a WordPress Site
- Rogue Drop-In Plugins: The infection installs a stealth file into
/wp-content/mu-plugins/(Must-Use plugins). These execute before standard security plugins initialize. - Blockchain RPC Calls: During page rendering, the script makes an outbound API call to a public blockchain RPC gateway (like Cloudflare Web3 or Infura) to read bytes from a specific contract address.
- In-Memory Code Execution: The received bytecode is decoded using PHP's
eval()or assembled in JavaScript to inject dynamic spam, phishing forms, or credential harvesting fields into your checkout page. - Self-Healing Cron Hooks: If you delete the file in
/wp-content/mu-plugins/, an automated system cron or database hook reinstalls it on the next cycle.
Why Surface Cleaning Fails
If your hosting provider simply "scans" the files, they will find and delete the dropper file. But because the cron hooks and database transients remain untouched, the file regenerates within hours.
To permanently eradicate an Etherhiding infection, the entire infrastructure must be locked down:
- Inbound and outbound unauthorized RPC connections blocked.
- All Must-Use plugins disinfected.
- Database wp_options transients cleared.
- System-level and WordPress-level cron queues flushed.
Delvok's emergency rescue service handles full forensic disinfection of advanced blockchain C2 infections with isolated container hosting so your site is never re-infected.