logo

Chinese actor compromises thousands of Wordpress sites

ID: 6670ba30-3754-54e5-b197-395f13e53ec7

STIX ID: report--6670ba30-3754-54e5-b197-395f13e53ec7

Feed Name: Ctrl-Alt-Int3l

Threat Score
85/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

Author: Ctrl-Alt-Intel

...
...

A June 2026 mass web-exploitation campaign abused dozens of vulnerable WordPress plugins and other CMS components to upload and execute PHP webshells, producing 25,195 confirmed compromised sites; retained artifacts include sophisticated webshells (down.php, Godzilla-compatible shells), VShell/SNOWLIGHT C2 infrastructure, exploitation scripts and PoCs, and attribution to a Chinese-speaking operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.