Malware
VShell
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
Indicators of Compromise 7
MITRE ATT&CK TTPs 8
T1027 T1055 T1059.001 T1071 T1071.001 T1087.002 T1090 T1190
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Domain Account
Discovery
Proxy
Command And Control
Exploit Public-Facing Application
Initial Access
Source Articles
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news ·2w ago
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.
bleeping-computer ·2w ago