Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
SNOWLIGHT
Malware
SNOWLIGHT
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
Indicators of Compromise
7
Domain
xs[.]xxooonline[.]eu[.]cc
Filename
.bd.php
Filename
.brq-*.php
Filename
.wp-log.php
Filename
down.php
IP
137[.]175[.]93[.]126
IP
43[.]108[.]17[.]80
MITRE ATT&CK TTPs
6
T1027
Obfuscated Files or Information
Defense Evasion
T1059.001
PowerShell
Execution
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1090
Proxy
Command And Control
T1190
Exploit Public-Facing Application
Initial Access
Source Articles
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news
·
2w ago