hacker-news · Crawled Jul 10, 2026
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
7 IoCs 1 Actors 2 Malware 2 CVEs
Read original article ↗
AI Summary
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 7 extracted
MITRE ATT&CK TTPs 24 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1059.001 PowerShell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1055 Process Injection · Defense Evasion T1087.002 Domain Account · Discovery T1021 Remote Services · Lateral Movement T1046 Network Service Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1505.003 Web Shell · Persistence T1566 Phishing · Initial Access T1053.003 Cron · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1075 T1075 T1083 File and Directory Discovery · Discovery T1485 Data Destruction · Impact T1490 Inhibit System Recovery · Impact