type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [web-shell, cybercrime-group, loader] ยท confidence: high ยท affected_sectors: [technology, media] ยท au_impact: false
WP-SHELLSTORM
WP-SHELLSTORM is a cybercriminal webshell access brokerage operation uncovered by Socradar after the operators accidentally left their command server exposed for three weeks, revealing target lists of over 1.4 million websites.
The Operation
- A cybercrime crew brokering access to backdoored websites via webshells
- The exposed server revealed detailed target lists: over 1.4 million websites catalogued
- Active backdoors installed on compromised WordPress sites
- Primarily exploited outdated plugins โ particularly the Breeze caching plugin and Joomla's JCE editor (raw/digests/Cyber-Digest-2026-07-11)
Discovery
- SOCRadar identified the operation after spotting the exposed folder on June 11, 2026
- Server exposed for three weeks before discovery
Implications
- Demonstrates the scale of webshell-based access markets
- Highlights the risk of outdated CMS plugins
- WordPress remains the most targeted CMS platform for backdoor installation
Related Pages
- Acsc Cms Exploitation โ ACSC warnings about CMS exploitation affecting Australia
- Lurking Lizard โ Another operation using compromised infrastructure