Chinese actor compromises thousands of Wordpress sites
ID: 6670ba30-3754-54e5-b197-395f13e53ec7
STIX ID: report--6670ba30-3754-54e5-b197-395f13e53ec7
Feed Name: Ctrl-Alt-Int3l
Threat Score
A June 2026 mass web-exploitation campaign abused dozens of vulnerable WordPress plugins and other CMS components to upload and execute PHP webshells, producing 25,195 confirmed compromised sites; retained artifacts include sophisticated webshells (down.php, Godzilla-compatible shells), VShell/SNOWLIGHT C2 infrastructure, exploitation scripts and PoCs, and attribution to a Chinese-speaking operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
