As cited
Copy frozen at (site build).
threat intel
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.
Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.
Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.
- Source published
- First seen by Cybersecurity Tracker