discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left a server open on the internet for three weeks, exposing its hacking tools, activity logs, and target lists naming over 1.4 million websites. The operation, tracked as WP-SHELLSTORM, is a webshell access brokerage that breaks into sites at scale, pla…

By Swati Khandelwal·Jul 10·thehackernews.com·3 min read

Intelligence analysis by Llama

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
Image: thehackernews.com

A cybercrime crew exposed its hacking tools and target lists, revealing a webshell access brokerage that breaks into sites at scale and packages access for resale. The operation, tracked as WP-SHELLSTORM, targeted over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.

Why it matters

The exposed server reveals a sophisticated hacking operation that could compromise thousands of websites, highlighting the need for website owners to keep their plugins up-to-date and secure.

Imagine a group of hackers who break into websites at a huge scale. They use automated tools to find vulnerabilities in website plugins and plant backdoors on the sites. They then sell access to these backdoors to other hackers. This group, called WP-SHELLSTORM, has been targeting over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.

Analysis

A Sophisticated Hacking Operation Exposed

The exposed server reveals a sophisticated hacking operation that has been targeting over 1.4 million websites. The operation, tracked as WP-SHELLSTORM, is a webshell access brokerage that breaks into sites at scale, plants backdoors, and packages access for resale. The strongest activity hit WordPress sites running out-of-date plugins, with the Breeze caching plugin being a major target. The crew used automated scanners to fire exploits at massive target lists, with the biggest producer being a bug in the Breeze caching plugin (CVE-2026-3844).

A Careless Crew

Despite running a sophisticated operation, the crew was careless in its tradecraft. It left the server open, left a FOFA search engine registration open, and used publicly known bugs in website plugins. The crew also used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2].

A History of Tooling

The tooling used by the crew has a history. The main backdoor, a file named down.php, was heavily obfuscated and appears to be derived from an open-source Chinese webshell called BestShell. The crew also used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2]. VShell itself is a common tool in Chinese-speaking criminal circles, so its presence alone doesn't point to a state actor.

A Sequence of Attacks

SOCRadar reads the timing as a sequence: grab high-value corporate credentials first, then pivot weeks later to the higher-volume backdoor work, a funding round before scaling up. The crew ran a quieter campaign in early May 2026 against corporate Java systems, pulling 613 configuration files from 11 systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics. The haul included cloud login keys for AWS, Alibaba Cloud, Oracle, Tencent, and DigitalOcean, database passwords, and Alipay RSA private keys.

Key points

  • A cybercrime crew exposed its hacking tools and target lists, revealing a webshell access brokerage that breaks into sites at scale and packages access for resale.
  • The operation, tracked as WP-SHELLSTORM, targeted over 1.4 million websites, with the strongest activity hitting WordPress sites running out-of-date plugins.
  • The crew used automated scanners to fire exploits at massive target lists, with the biggest producer being a bug in the Breeze caching plugin (CVE-2026-3844).
  • The crew was careless in its tradecraft, leaving the server open and using publicly known bugs in website plugins.
  • The tooling used by the crew has a history, with the main backdoor being heavily obfuscated and derived from an open-source Chinese webshell called BestShell.
The Upside

If the exposed server is shut down and the crew's tooling is taken down, it could prevent further hacking operations and protect thousands of websites from being compromised.

The Downside

If the crew is able to recover from the exposure and continue its operations, it could lead to a significant increase in website hacking and compromise, with potentially devastating consequences for website owners and users.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityhackingwebshellwordpressjoomlapluginexploitbackdoorcybercrime

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Jul 10, 2026

Source

thehackernews.com

Share

Topics

securityhackingwebshellwordpressjoomlapluginexploitbackdoorcybercrime

Related

More from this desk

Aug 26·bleepingcomputer.com

Critical Avada WordPress theme flaw enables zero-click RCE

Critical vulnerability in Avada WordPress theme can be exploited for arbitrary PHP code execution. CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

Aug 26·bleepingcomputer.com

New GPUThor attack defeats NVIDIA ECC protection for root access

Researchers demonstrate a new Rowhammer attack called GPUThor that can bypass ECC protections on NVIDIA GPUs, leading to DoS and privilege escalation.

Aug 26·thehackernews.com

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts QTFY hacking platforms used by Chinese threat actors to target U.S. critical infrastructure and sensitive networks.

Aug 26·bleepingcomputer.com

Boston Scientific Announces Cyberattack Disrupts Global Operations

Boston Scientific reports a cyberattack that disrupted its IT systems, causing operational disruptions globally. The company is working to restore affected functions and systems access.