hacker-news · Crawled Jul 10, 2026

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

7 IoCs 1 Actors 2 Malware 2 CVEs
Read original article ↗

AI Summary

A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.

AI-extracted · verify before operational use

Extracted Entities 5 found

Indicators of Compromise 7 extracted

Type Value Detail
IP 137[.]175[.]93[.]126 Details →
IP 43[.]108[.]17[.]80 Details →
Domain xs[.]xxooonline[.]eu[.]cc Details →
Filename down.php Details →
Filename .bd.php Details →
Filename .wp-log.php Details →
Filename .brq-*.php Details →

MITRE ATT&CK TTPs 24 techniques