WP-SHELLSTORM is a financially motivated cybercrime operation assessed with medium-to-high confidence to be Chinese or Chinese-speaking. The group functions primarily as a webshell access brokerage: it mass-exploits known vulnerabilities in internet-facing web applications, implants covert webshell backdoors on compromised sites, and packages or resells that access. Activity attributed to the operation has centered on large-scale exploitation of WordPress and Joomla ecosystems, with particular success from exploiting CVE-2026-3844 in the Breeze caching plugin. Reporting on the group indicates that its infrastructure, logs, and tooling exposed target lists covering more than 1.4 million websites, although that figure reflected scanned or queued targets rather than confirmed compromises; validated compromise estimates ranged from several thousand active webshells to more than 25,000 deduplicated affected sites. The operation relies on automated scanning and exploitation against publicly known vulnerabilities, including broad use of internet-exposed asset discovery platforms to assemble target lists. Its tooling included exploit scripts, scan results, command history, and command-and-control settings spanning dozens of vulnerabilities across WordPress, Joomla, and other platforms. The group’s principal webshell was an obfuscated implant derived from the Chinese open-source BestShell family. Observed capabilities included remote command execution, file management, reverse shell access, internal network scanning, and identification of security software on compromised hosts. The operators also used the SNOWLIGHT dropper to deploy the VShell backdoor for more persistent remote access, while disguising processes to blend with normal Linux activity. Beyond website compromise, the same operators were linked to an earlier campaign against exposed Nacos systems in which they bypassed authentication and stole configuration files and embedded secrets from corporate environments. Stolen data reportedly included cloud credentials, database passwords, and cryptographic material from organizations in fintech, e-commerce, logistics, gaming, and electronics. This broader activity shows that WP-SHELLSTORM is not limited to simple website defacement or opportunistic shell placement, but is capable of post-compromise credential theft, data exfiltration, and follow-on monetization of access. Although some tooling overlaps with malware and tradecraft seen in Chinese intrusion sets, available evidence supports classification of WP-SHELLSTORM as a criminal operation rather than a state-directed actor. No high-confidence sub-group structure is established from the available facts. Known aliases are limited to WP-SHELLSTORM.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Используя старую уязвимость CVE-2021-29441 в Nacos, атакующие похитили 613 конфигурационных файлов с ключами AWS, Alibaba Cloud, Oracle, Tencent и DigitalOcean, паролями от БД и приватными RSA-ключами Alipay.
Наиболее эффективным для проведения таких атак оказался баг CVE-2026-3844 в кеширующем плагине Breeze. Эксплоит для этой уязвимости использовали против более чем 45 000 сайтов, а веб-шелл, судя по логам атакующих, удалось установить более чем на 17 000 из них.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as background context for prior mass exploitation of WordPress sites via a caching-plugin flaw.
A financially motivated webshell access brokerage operation conducting mass exploitation of vulnerable WordPress, Joomla, and some enterprise Java systems to plant webshells, steal credentials, and resell access at scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.