Can a Backup Contain Malware?
A Backup — a Lifeline or a Source of Trouble?
A backup should be a safety net. However, for infected sites, it often becomes a source of reinfection. This happens because most automatic backups run continuously — and do not distinguish clean files from infected ones.
How Does Malware Get into a Backup?
Most hosting providers make automatic backups every 24 hours or every week. The problem arises when:
- The infection occurred several days or weeks before it was detected (which happens very often — hackers deliberately hide the symptoms)
- The backup overwrote an old version — meaning infected files replaced those from before the attack
- The backup includes only files, not the database — or vice versa
- Backups are retained for 7 days, while the infection has already been active for 10 days — all available copies are contaminated
In this situation, restoring a backup does not return the site to its pre-attack state — it restores it to a state with an active infection.
How to Check Whether a Backup Is Clean
Before restoring a backup, carry out a few verification steps:
1. Check the Backup Date Against the Infection Date
Establish approximately when the infection occurred (the date of the first symptoms, changes to file modification dates, access logs). A backup from before that date is potentially clean. A backup from the same period or later is probably infected.
2. Scan the Archive Before Restoring It
Extract the backup locally (on your own computer or in an isolated test environment) and scan it with antivirus software. You can use tools such as ClamAV (free, available on Linux/Mac) or upload the extracted files to VirusTotal.
3. Check the Database
An SQL database export is a text file — you can open it in an editor and search for patterns such as eval(base64_decode, <script src= in non-HTML fields, or suspicious URLs in the wp_options table.
What If All Backups Are Infected?
This is a difficult situation, but not a hopeless one. Options:
- Clean installation + content migration — instead of restoring an infected backup, install WordPress from scratch and manually transfer content (posts, images, pages) from the database or an XML export. Download themes and plugins from fresh sources.
- Clean the infected backup — a specialist removes malware from the archive before restoration, removing malicious code from files and the database.
- A copy from the hosting server — some hosting providers keep backups for 30 or 90 days in a separate location. It is worth asking support whether they have older backups that are not available in the customer panel.
How to Back Up Safely in the Future
It is worth implementing a backup strategy that minimizes the risk of all copies becoming infected:
- Retention of at least 30 days — most infections are detected within 2 weeks; a 30-day window provides a safe margin
- Off-server copies — a backup stored only on the same server may be overwritten or deleted by hackers
- Backup verification — perform a test restoration in a staging environment once a month to make sure the backup works and is complete
- Separate file and database backups with timestamps — the ability to restore files from one day and the database from another