Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and Joomla sites, resulted in over 1.4 million targeted domains, though only a fraction were actually compromised. The exposure stemmed from a careless mistake: the operator forgot to close the server, revealing a sophisticated, yet ultimately simple, operation that relied on publicly available exploits and automated scanning. The crew's tactics, including using a Chinese-speaking operation and targeting corporate credentials, highlight a common pattern of exploiting readily available vulnerabilities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
