An exposed server tied to the WP-SHELLSTORM cybercrime operation revealed tooling, logs, command history, and target lists for a large-scale webshell campaign aimed primarily at WordPress sites, with additional targeting of Joomla and enterprise Java platforms. Researchers said the group scanned more than 1.4 million domains, exploited 27 CVEs—including the Breeze plugin flaw CVE-2026-3844—and maintained roughly 5,700 active webshells, while some analysis put validated compromises as high as 25,195. The operation used layered implants including BestShell-derived webshells, a SNOWLIGHT dropper, and a VShell payload disguised as a Linux kworker process, then resold access to compromised websites.
The exposed infrastructure also linked the operators to a separate campaign against Nacos deployments, where they exploited the authentication bypass CVE-2021-29441 and stole 613 configuration files from 11 systems across nine organizations. Investigators assessed the activity with medium-to-high confidence as financially motivated and likely conducted by Chinese or Chinese-speaking operators rather than a state-backed APT, citing Simplified Chinese artifacts, FOFA usage, and overlap between the web and Java intrusion sets. The operators reportedly tried to alter access logs after the server was discovered, but the exposure had already disclosed extensive indicators of compromise and operational details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The report said WP-SHELLSTORM weaponized 27 CVEs affecting WordPress plugins and Joomla components, and linked the operation to follow-on tooling including the SNOWLIGHT stager and the VShell implant. Researchers also published indicators such as IP addresses, a domain, and a SHA-256 hash for a primary webshell.
After apparently realizing the exposed server had been discovered, the actor appeared to modify or tamper with access logs. By that point, the exposure had already revealed substantial operational details and indicators of compromise.
Based on artifacts including FOFA usage, Simplified Chinese traces, and overlap between the WordPress and Java activity, researchers assessed with medium-to-high confidence that the operators were Chinese or Chinese-speaking. They judged the campaign to be professional and financially motivated rather than state-directed.
The exposed data showed a financially motivated webshell access-brokerage operation targeting more than 1.4 million domains, primarily exploiting WordPress and Joomla vulnerabilities at scale. Researchers said the figure reflected scanned targets, while compromise estimates ranged from about 5,700 active webshells to 25,195 validated compromises.
In May 2026, the actor exploited Nacos authentication bypass CVE-2021-29441 in a related campaign and stole 613 configuration files from 11 victim systems across nine organizations.
Researchers discovered that a Python SimpleHTTPServer directory on 137.175.93[.]126 was exposed for 22 days, revealing the operator's tools, logs, target lists, and command infrastructure for the WP-SHELLSTORM operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourcesocradar.io
Open sourcectrlaltintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.