SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Inside WP-SHELLSTORM: Uncovering the Infrastructure Targeting Millions of WordPress Sites

Inside WP-SHELLSTORM: Uncovering the Infrastructure Targeting Millions of WordPress Sites

Jul 14, 2026By Padmashree P

Summary

WP-SHELLSTORM is a large-scale webshell access operation that used automated vulnerability scanning, publicly available exploits, and extensive target lists to compromise vulnerable WordPress, Joomla, and other internet-facing websites. The campaign operationalized multiple known vulnerabilities—including CVE-2026-3844 (Breeze WordPress plugin), CVE-2026-48907 (Joomla JCE Editor), CVE-2026-3300 (Everest Forms Pro), CVE-2026-1969 (ThemeREX Addons), CVE-2020-36847 (Simple File List), CVE-2020-25213 (WP File Manager), and CVE-2021-29441 (Alibaba Nacos)—to automate exploitation and deploy persistent webshells. The campaign became visible after an attacker-controlled server was inadvertently exposed without authentication for approximately three weeks, revealing exploit scripts, webshells, scan results, command histories, target lists, and command-and-control configuration data.

The exposed infrastructure contained more than 1.4 million target entries. This figure represents websites selected for scanning rather than confirmed compromises. Researchers reported substantially lower compromise totals, including more than 25,000 sites with validated evidence of compromise and over 5,700 active webshells, depending on the methodology used. The operation demonstrates how attackers can combine known vulnerabilities, automated scanners, and reusable backdoors to build access inventories at scale without relying on zero-day vulnerabilities.

Background of WP-SHELLSTORM

WP-SHELLSTORM is tracked as a webshell access brokerage operation. Instead of compromising websites solely for immediate defacement or data theft, the operators systematically identify vulnerable sites, deploy persistent webshells, validate access, and maintain an inventory that can potentially be used or resold for future malicious activity.

The campaign's internal infrastructure was discovered on a rented server hosted at 137.175.93[.]126. The server reportedly exposed an open directory containing approximately 800 MB of data across 434 files. The material included exploitation frameworks, target lists, malware components, command histories, webshells, scanning results, and operational configuration files.

The operators obtained large target lists from internet asset-search platforms and fed them into automated scanners. These scanners fingerprinted websites, identified vulnerable plugin or component versions, and attempted exploitation at scale. When exploitation succeeded, the attacker uploaded a webshell that could execute commands, manipulate files, establish reverse shells, collect credentials, and support deeper compromise of the hosting environment.

Campaign Overview

Attribute Details
Campaign Name WP-SHELLSTORM
Threat Model Mass website exploitation and webshell access brokerage
Primary Targets WordPress, Joomla, and other vulnerable internet-facing web applications
Target List Size More than 1.4 million website entries
Validated Compromise Estimates More than 25,000 sites with validated compromise evidence, with another analysis identifying more than 5,700 active webshells
Primary Objective Deploy persistent webshells and establish reusable unauthorized access
Initial Access Exploitation of known vulnerabilities in plugins, extensions, and exposed enterprise applications
Primary Backdoor Obfuscated PHP webshell, including a file identified as down.php
Additional Tooling SNOWLIGHT dropper, VShell backdoor, automated scanners, exploit scripts, and reverse shells
Assessed Motivation Financially motivated access collection and potential resale

Vulnerability Details

CVE ID Affected Product or Component Vulnerability Type Campaign Relevance
CVE-2026-48907 Joomla JCE Editor Unauthenticated file upload and remote code execution Targeted at significant scale. Although the campaign recorded relatively few successful compromises through this vulnerability, it remains a critical actively exploited risk.
CVE-2020-25213 WP File Manager WordPress plugin Unauthenticated remote code execution A widely exploited legacy vulnerability incorporated into the campaign's mass-scanning toolkit.

Attack Methodology

  • Phase 1: Target Collection and Fingerprinting
    The operators gather large lists of internet-facing websites from public asset-search services and use automated scanners to identify content management systems, installed plugins, exposed paths, component versions, and other indicators of potential vulnerability.
  • Phase 2: Vulnerability Matching and Exploitation
    Fingerprinting results are compared against the campaign's exploit collection. Automated scripts then target vulnerable plugins, extensions, and web application components to bypass authentication, upload files, modify server-side content, or execute commands.
  • Phase 3: Webshell Deployment
    After successful exploitation, the attackers upload an obfuscated PHP webshell that provides file management, command execution, reverse-shell access, network scanning, and security-product discovery capabilities.
  • Phase 4: Access Validation and Persistence
    The operators verify that each deployed webshell remains reachable and functional. Additional payloads, including SNOWLIGHT and VShell, may be installed to maintain persistent access and disguise malicious processes as legitimate Linux kernel worker threads.
  • Phase 5: Credential Collection and Internal Discovery
    Webshell access is used to inspect configuration files, read databases, collect credentials, retrieve application secrets, identify cloud or payment-related keys, and discover additional systems or services reachable from the compromised server.
  • Phase 6: Access Brokerage and Follow-on Abuse
    Validated access is retained, organized, transferred, or sold to other threat actors for spam distribution, malware hosting, traffic redirection, credential theft, cryptomining, or deeper intrusion into connected environments.

Indicators of Compromise (IOCs)

Known Infrastructure

137.175.93[.]126
43.108.17[.]80

Suspicious Webshell Filename Patterns

.bd.php
.wp-log.php

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic
T1595.002 Active Scanning: Vulnerability Scanning Reconnaissance
T1190 Exploit Public-Facing Application Initial Access
T1505.003 Server Software Component: Web Shell Persistence
T1059.004 Command and Scripting Interpreter: Unix Shell Execution
T1105 Ingress Tool Transfer Command and Control
T1036.004 Masquerading: Masquerade Task or Service Defense Evasion
T1083 File and Directory Discovery Discovery
T1046 Network Service Discovery Discovery
T1552.001 Unsecured Credentials: Credentials in Files Credential Access
T1005 Data from Local System Collection
T1071.001 Application Layer Protocol: Web Protocols Command and Control

Visual Attack Flow

Mitigation

  1. Patch the Breeze WordPress plugin.
    Upgrade Breeze to a version that remediates CVE-2026-3844. Environments using the non-default Host Files Locally – Gravatars option should be prioritized because the campaign's exploitation path depended on that setting.
  2. Update Joomla JCE immediately.
    Upgrade JCE Editor to version 2.9.99.5 or later. Treat systems exposed while running a vulnerable version as potentially compromised and investigate them rather than assuming that patching alone removes an existing webshell.
  3. Patch all affected WordPress plugins.
    Review and update ThemeREX Addons, Everest Forms Pro, Simple File List, Custom CSS JS PHP, BerqWP, Ninja Forms, WavePlayer, WPBookit, WP File Manager, and any other plugin identified in the campaign's exploit inventory. Remove plugins that are unused, abandoned, or no longer supported by their developers.
  4. Remove unsupported and unnecessary extensions.
    Every installed plugin or extension expands the website's attack surface. Disable and delete components that are not operationally required. Do not leave inactive plugins installed, because their vulnerable files may remain reachable from the internet.

Inst​​antly Fix Risks with Saner Patch Management

Saner Patch Management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here .

Featured Posts

Open One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting
One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

CVE Research

One Request, Total Persistence: Inside the SharePoint Flaw Attackers Are Exploiting

A critical SharePoint deserialization flaw, CVE-2026-50522 (CVSS 9.8), is under active exploitation just weeks after its July 2026 patch, following a public PoC. Attackers are using it to steal IIS machine keys in a single request, gaining persistence that survives patching alone. Now on CISA's KEV list, it's the third actively exploited SharePoint flaw in recent months, patch immediately and rotate machine keys.

Jul 24, 2026

Open ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack
ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

CVE Research

ENCFORGE Ransomware: Anatomy of an AI-Focused Cyber Attack

Jul 22, 2026

Open UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain
UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

CVE Research

UTA0533 Weaponizes KNUCKLEBALL: Inside the SonicWall SMA Zero-Day Exploitation Chain

Jul 20, 2026

Open One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw
One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

CVE Research

One Email, Full Session Takeover: Inside Zimbra's Critical Classic Web Client Code Execution Flaw

Jul 20, 2026