Also known as: tracked as
WP‑SHELLSTORM emerged publicly when investigators discovered an unintentionally exposed Python SimpleHTTPServer hosting a directory of the group’s toolset, logs, and target lists. Analysis revealed that the actor had deployed more than 5,700 active webshells across WordPress and Joomla environments, leveraging a suite of over 27 known plugin CVEs. The operation was automated, with scripts first identifying vulnerable sites, then delivering exploitation payloads to install persistent backdoors (e.g., VShell). Beyond standard web shell implantation, WP‑SHELLSTORM also engaged in credential‑theft against Java applications by targeting the Nacos configuration server vulnerability (CVE‑2021‑29441) and exfiltrated sensitive cloud credentials, database passwords, and payment system keys from multiple victims. The group’s infrastructure was further illuminated by a mass-exposures attack on an IP range that revealed their command‑and‑control activity, the presence of tools such as SNOWLIGHT and down.php, and evidence of botnet‑like network coverage. This dual‑faceted campaign—mass CMS exploitation combined with targeted Java system credential harvests—highlights WP‑SHELLSTORM’s sophisticated use of publicly available exploit code, automated reconnaissance, and a revenue model based on access brokerage. Their operations demonstrate an ability to move from initial vulnerability exploitation through persistence, exfiltration, and monetization while attempting to conceal infrastructure through obfuscated webshells that mimic legitimate processes.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
WP‑SHELLSTORM is a financially motivated cybercriminal group that conducted a large‑scale automated webshell campaign against over 1.4 million WordPress and Joomla sites by exploiting CVE‑2026‑3844 (Breeze) and CVE‑2026‑48907 (JCE Editor). The attackers monetize compromised access through resale or rent of backdoored control to other actors, while also conducting credential‑theft operations against Java‑based systems such as Nacos. Their tactics span multiple sectors in India, China, North Korea, Vietnam, and Australia, making them a high‑impact threat for any organization running vulnerable CMS platforms.
Goals & Targeting
WP‑SHELLSTORM’s primary objective is financial gain achieved by creating a large inventory of compromised web servers that can be sold or rented to other threat actors. The group focuses on publicly facing content management systems—especially WordPress and Joomla—leveraging high‑volume, low‑effort exploitation tactics. Victim selection spans critical infrastructure, government, healthcare, retail, finance, education, aviation, utilities, transport, gaming and media sectors across India, China, North Korea, Vietnam and Australia. The actor also extends its reach into cloud‑native services via credential theft from Java applications, demonstrating a layered approach to monetization: 1) exploit weak plugins for webshell access; 2) sell or lease that access; 3) exfiltrate high‑value credentials for additional revenue streams.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
WP‑SHELLSTORM’s operations are characterized by high-volume, automated exploitation of well-known CMS plugins, resulting in a catalog of over 25,000 compromised sites. The campaign’s tempo is rapid, with mass scanning and payload delivery occurring in minutes to hours, reflecting the group’s use of botnet infrastructure and automated scripts. Victims span a wide array of industries in South Asian and Southeast Asian regions, but incidents have also been detected in Australian organizations. While primarily focused on webshell creation, the actor has performed more sophisticated credential‑theft against Java-based cloud services, indicating a willingness to diversify attack vectors for additional monetization opportunities.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
7
Techniques
54
Tools
0
Campaigns
26
IOCs
0
Observed Data
5
Tactics