CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2321

As cited

Copy frozen at (site build).

threat intel

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.

Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.

Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary