Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
ID: 0d144688-d05d-5353-9010-2a44f5315d71
STIX ID: report--0d144688-d05d-5353-9010-2a44f5315d71
Feed Name: The Hacker News
WP-SHELLSTORM is a financially-motivated webshell access brokerage whose operator left an unsecured server that exposed webshells, exploit scripts, scan results and target lists covering ~1.4M domains; researchers validated thousands of compromised WordPress/Joomla sites and recovered tooling (obfuscated down.php, SNOWLIGHT dropper, VShell) plus evidence of earlier credential theft from Nacos instances — the disclosure includes exploited CVEs, IoCs (IPs/domains, webshell filenames, process artefacts) and prioritized patching/hunt guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
