news.mlab.sh
Back to the feed
threat-intel

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

High
Image: The Hacker News
Summary

A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and Joomla sites, resulted in over 1.4 million targeted domains, though only a fraction were actually compromised. The exposure stemmed from a careless mistake: the operator forgot to close the server, revealing a sophisticated, yet ultimately simple, operation that relied on publicly available exploits and automated scanning. The crew's tactics, including using a Chinese-speaking operation and targeting corporate credentials, highlight a common pattern of exploiting readily available vulnerabilities.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.