CVE Tools
Back to feed
PoC public Adobe Acrobat Chrome extension web-app Adobe info-disclosure

Сервер хакеров WP-SHELLSTORM раскрывал данные о тысячах атак

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Researchers discovered an unsecured server belonging to a hacking group that mass-compromised WordPress and Joomla sites, installing web shells. Files contained lists of 1.4 million potential targets, exploits, logs, and details of successful attacks under the campaign name WP-SHELLSTORM. The server at 137.175.93.126 was left password-free and hosted around 800 MB of data including 434 files with web shells, scripts, scanning results, infrastructure settings, and command history. A human error caused the leak— one attacker ran a simple HTTP server in Python for file sharing but failed to disable it for 22 days. Attackers used the Chinese search engine FOFA to compile their list of targets and scanned them for 27 known vulnerabilities, primarily in WordPress plugins. The most effective exploit was CVE-2026-3844 in the caching plugin Breeze, which was used against over 45,000 websites, successfully deploying web shells on more than 17,000. While attackers listed approximately 1.4 million domains as targets, the actual number of compromised sites was lower. Analysts identified 25,195 resources showing signs of compromise, while SOCRadar found over 5,700 active web shells. The main tool used by the hacker group was an obfuscated file named down.php, likely based on the Chinese web shell BestShell. It allowed file manipulation, command execution, reverse shells, network scanning, and checking installed security software. To access their own infrastructure, the group used the dropper SNOWLIGHT and backdoor VShell, which masked its process name as a kernel thread. Additionally, researchers found traces of another malicious campaign where attackers compromised 11 Java systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics using the old vulnerability CVE-2021-29441 in Nacos. They stole 613 configuration files containing AWS, Alibaba Cloud, Oracle, Tencent, and DigitalOcean keys, database passwords, and private RSA keys from Alipay.