Find notable cyber news and cases, enriched with sources, timelines, and signals.

WP-SHELLSTORM webshell access brokerage campaign

Campaign
First reported
Last updated
Happening score
H score 71
2 unique sources, 2 articles

Summary

Hide ▲

The WP-SHELLSTORM campaign exposed its own infrastructure, revealing a webshell access brokerage that targeted WordPress and Joomla sites at scale and backdoored thousands of sites. The exposed files contained webshells, exploit scripts, scan results, command history, and target lists naming more than 1.4 million websites. The operation relied on automated scanning of public flaws such as CVE-2026-3844 to plant backdoors for later resale. Separate files show an earlier phase that harvested cloud credentials and other secrets from corporate Java systems before the large-scale webshell push.

Related Happenings

Joomla iCagenda and Balbooa Forms active RCE exploitation wave

Exploitation Wave
H score42 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: Joomla sites were hit by an active exploitation wave against iCagenda and Balbooa Forms upload flaws, enabling remote code execution and full website takeover....

Joomla extensions arbitrary file upload (multiple vulnerabilities, actively exploited)

Vulnerability
H score59 First: 13.07.2026 08:36 Last: 13.07.2026 08:36 Sources 1

About this happening: CISA added CVE-2026-48939 and CVE-2026-56291 to the KEV catalog, confirming zero-day exploitation of two Joomla extension flaws that allow arbitrary file u...

SNOWLIGHT-to-VShell remote-access backdoor chain

Malware Activity
H score51 First: 10.07.2026 14:30 Last: 10.07.2026 14:30 Sources 1

How related: For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list.

About this happening: The SNOWLIGHT dropper was used to install VShell, giving operators covert remote access on compromised hosts and hiding the backdoor as [kworker/0:2] in process li...

Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign

Campaign
H score36 First: 26.05.2026 10:13 Last: 26.05.2026 10:13 Sources 1

About this happening: Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...

Shai-Hulud worm clone activity on NPM

Malware Activity
H score69 First: 18.05.2026 12:45 Last: 18.05.2026 12:45 Sources 1

About this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...

Timeline

  1. 10.07.2026 14:30 1 articles · 13d ago

    SOCRadar finds exposed WP-SHELLSTORM server on 137.175.93[.]126

    Detection Ioc Update

    SOCRadar's threat intelligence team found a US-based rented server at 137.175.93[.]126 with no password protection, exposing roughly 800MB across 434 files that included webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings. The exposure appears to have come from a simple Python web server left running for 22 days.

    Show sources
  2. 09.07.2026 03:00 3 articles · 15d ago

    SOCRadar details WP-SHELLSTORM webshell access brokerage

    Technical Analysis Update

    SOCRadar describes WP-SHELLSTORM as a webshell access brokerage that used automated scanners against FOFA-derived target lists to hit WordPress and Joomla flaws, plant webshell backdoors for resale, and operate tools such as down.php, SNOWLIGHT, and VShell. The same analysis also traces an earlier campaign in early May 2026 against corporate Java systems that pulled 613 configuration files and cloud credentials from 11 systems across nine companies.

    Show sources