The new face of malware: why “scan and delete” no longer works
Modern WordPress malware doesn’t drop an obvious rogue file anymore—it hides inside the files you already trust. A basic scanner can miss it entirely.
For years, “clean a hacked WordPress site” meant scanning for unfamiliar files and deleting them. That approach is losing effectiveness fast. The 2026 threat data from Patchstack and malware intelligence firm Monarx shows attackers increasingly injecting malicious code directly into legitimate WordPress core, plugin, and theme files, rather than dropping standalone files a scanner can flag as foreign.
Malware that survives being “cleaned”
One malware family documented in 2026, tracked as Lock360, runs persistently in server memory and reinfects cleaned files—including index.php—the moment they’re restored from a backup. That’s a fundamentally different problem than a single infected file: the infection point is the running process, not just the file on disk, so a surface-level cleanup simply gets overwritten again.
Even trusted plugins aren’t automatically safe
In April 2026, attackers compromised over 30 widely used WordPress plugins by inserting backdoor malware directly into official plugin updates—a supply-chain attack that let them remotely control affected sites and inject SEO spam for months before detection. WordPress.org removed more than 25 plugins in a single day in response. Cloaking techniques have also evolved to specifically target AI crawlers, hiding spam content from human moderators while still feeding it to search and AI indexes.
- Assume infected files may be legitimate core, plugin, or theme files, not just obvious intruders.
- Use a cleanup process that checks for persistent, memory-resident reinfection, not just file scans.
- Audit plugin updates and remove anything no longer actively maintained by its developer.
- Re-scan after cleanup—a clean scan today doesn’t guarantee a clean site next week.
“Attackers are now injecting code into legitimate WordPress core, plugin, and theme files rather than dropping standalone malicious files—traditional scan-and-delete misses this entirely.”
Not sure if a previous “cleanup” actually worked?
We check for persistent, code-injected infections that basic scanners miss.
What this means for your business
A malware removal service built around deleting obviously suspicious files is increasingly fighting yesterday’s threat. If your site was “cleaned” once and quietly got reinfected, that’s not bad luck—it’s a strong sign the original cleanup only addressed the symptom, not the injection point.
Key takeaways
- Modern malware hides inside legitimate core, plugin, and theme files, not standalone rogue files.
- Some malware persists in server memory and reinfects files after they’re restored.
- Even official, trusted plugins have been compromised through supply-chain attacks.
- A proper cleanup checks for reinfection sources, not just visible symptoms.
Get a real malware diagnosis, not just a scan
We identify the actual infection point, clean it properly, and guarantee it stays gone for 30 days.
Get emergency help
Leave a Reply