logo

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

ID: 0d144688-d05d-5353-9010-2a44f5315d71

STIX ID: report--0d144688-d05d-5353-9010-2a44f5315d71

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

WP-SHELLSTORM is a financially-motivated webshell access brokerage whose operator left an unsecured server that exposed webshells, exploit scripts, scan results and target lists covering ~1.4M domains; researchers validated thousands of compromised WordPress/Joomla sites and recovered tooling (obfuscated down.php, SNOWLIGHT dropper, VShell) plus evidence of earlier credential theft from Nacos instances — the disclosure includes exploited CVEs, IoCs (IPs/domains, webshell filenames, process artefacts) and prioritized patching/hunt guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.