Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left a server open on the internet for three weeks, exposing its hacking tools, activity logs, and target lists naming over 1.4 million websites. The operation, tracked as WP-SHELLSTORM, is a webshell access brokerage that breaks into sites at scale, pla…
Intelligence analysis by Llama

A cybercrime crew exposed its hacking tools and target lists, revealing a webshell access brokerage that breaks into sites at scale and packages access for resale. The operation, tracked as WP-SHELLSTORM, targeted over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.
Imagine a group of hackers who break into websites at a huge scale. They use automated tools to find vulnerabilities in website plugins and plant backdoors on the sites. They then sell access to these backdoors to other hackers. This group, called WP-SHELLSTORM, has been targeting over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.
Analysis
A Sophisticated Hacking Operation Exposed
The exposed server reveals a sophisticated hacking operation that has been targeting over 1.4 million websites. The operation, tracked as WP-SHELLSTORM, is a webshell access brokerage that breaks into sites at scale, plants backdoors, and packages access for resale. The strongest activity hit WordPress sites running out-of-date plugins, with the Breeze caching plugin being a major target. The crew used automated scanners to fire exploits at massive target lists, with the biggest producer being a bug in the Breeze caching plugin (CVE-2026-3844).
A Careless Crew
Despite running a sophisticated operation, the crew was careless in its tradecraft. It left the server open, left a FOFA search engine registration open, and used publicly known bugs in website plugins. The crew also used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2].
A History of Tooling
The tooling used by the crew has a history. The main backdoor, a file named down.php, was heavily obfuscated and appears to be derived from an open-source Chinese webshell called BestShell. The crew also used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2]. VShell itself is a common tool in Chinese-speaking criminal circles, so its presence alone doesn't point to a state actor.
A Sequence of Attacks
SOCRadar reads the timing as a sequence: grab high-value corporate credentials first, then pivot weeks later to the higher-volume backdoor work, a funding round before scaling up. The crew ran a quieter campaign in early May 2026 against corporate Java systems, pulling 613 configuration files from 11 systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics. The haul included cloud login keys for AWS, Alibaba Cloud, Oracle, Tencent, and DigitalOcean, database passwords, and Alipay RSA private keys.
Key points
- A cybercrime crew exposed its hacking tools and target lists, revealing a webshell access brokerage that breaks into sites at scale and packages access for resale.
- The operation, tracked as WP-SHELLSTORM, targeted over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.
- The crew used automated scanners to fire exploits at massive target lists, with the biggest producer being a bug in the Breeze caching plugin (CVE-2026-3844).
- The crew was careless in its tradecraft, leaving the server open and using publicly known bugs in website plugins.
- The tooling used by the crew has a history, with the main backdoor being heavily obfuscated and derived from an open-source Chinese webshell called BestShell.
If the exposed server is shut down and the crew's tooling is taken down, it could prevent further hacking operations and protect thousands of websites from being compromised.
If the crew is able to recover from the exposure and continue its operations, it could lead to a significant increase in website hacking and compromise, with potentially devastating consequences for website owners and users.



