Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [web-shell, cybercrime-group, loader] ยท confidence: high ยท affected_sectors: [technology, media] ยท au_impact: false

WP-SHELLSTORM

WP-SHELLSTORM is a cybercriminal webshell access brokerage operation uncovered by Socradar after the operators accidentally left their command server exposed for three weeks, revealing target lists of over 1.4 million websites.

The Operation

  • A cybercrime crew brokering access to backdoored websites via webshells
  • The exposed server revealed detailed target lists: over 1.4 million websites catalogued
  • Active backdoors installed on compromised WordPress sites
  • Primarily exploited outdated plugins โ€” particularly the Breeze caching plugin and Joomla's JCE editor (raw/digests/Cyber-Digest-2026-07-11)

Discovery

  • SOCRadar identified the operation after spotting the exposed folder on June 11, 2026
  • Server exposed for three weeks before discovery

Implications

  • Demonstrates the scale of webshell-based access markets
  • Highlights the risk of outdated CMS plugins
  • WordPress remains the most targeted CMS platform for backdoor installation

Related Pages