2026-07-10NOTABLEexploitedSOCRadar finds a webshell-brokerage crew's own open staging server, 5,700+ live shells, 27 weaponized CVEs, and a parallel Nacos/Spring Boot credential heist
WP-SHELLSTORM
actor · actor:wp-shellstorm
SOCRadar designation for a financially-motivated, assessed Chinese-speaking webshell access-brokerage crew (WABO) whose own unauthenticated staging server, exposed for 22 days, revealed automated exploitation of 27 weaponized CVEs against ~1.4M WordPress/Joomla domains (5,700+ live webshells; a Breeze Cache Cleaner flaw CVE-2026-3844 the highest-yield) plus a parallel Apache Nacos/XXL-Job/Spring Boot cloud-credential-theft track using CVE-2021-29441 and JDumpSpider; deploys BestShell-derived and Godzilla webshells and a VShell implant that masquerades as a Linux kernel worker thread (SOCRadar, 2026-07-09; corroborated by Ctrl-Alt-Intel via The Hacker News, 2026-07-10).
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
SOCRadar finds a webshell-brokerage crew's own open staging server, 5,700+ live shells, 27 weaponized CVEs…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, technology
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about WP-SHELLSTORM, newest first. Check the date before acting on an older one.
- Update or disable the directly-targeted plugins now if you run them: Breeze Cache (CVE-2026-3844) and ThemeREX Addons (CVE-2026-1969); scan WordPress/Joomla web-writable directories (uploads, plugin dirs) for unexpected PHP files and treat any as a web shell until cleared.2026-07-10SOCRadar finds a webshell-brokerage crew's own open…
- If you run Apache Nacos, upgrade to ≥ 2.2.1 with nacos.core.auth.enabled=true and rotate every credential that lived in an exposed instance; test exposure by confirming a 'Nacos-Server' User-Agent request against the cluster-nodes endpoint (CVE-2021-29441) returns no data without auth.2026-07-10SOCRadar finds a webshell-brokerage crew's own open…
- Disable /actuator/heapdump in production and lock all Spring Boot Actuator endpoints behind authentication; close and segment unauthenticated XXL-Job executor endpoints from the internet.2026-07-10SOCRadar finds a webshell-brokerage crew's own open…
Defender insights
What each entry about WP-SHELLSTORM tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (5 across 5 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
- StealthMasquerading: Masquerade Task or Service
- Credential AccessUnsecured Credentials: Credentials In Files
- Command and ControlApplication Layer Protocol: Web Protocols
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit · ATT&CK page ↗
Stealth TA0005
T1036.004Masquerading: Masquerade Task or Service×1
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.
Evidence: 2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-10/wp-shellstorm-webshell-brokerage-exposed-toolkit · ATT&CK page ↗
Entries about WP-SHELLSTORM (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- socradar.io1 (50%)
- thehackernews.com1 (50%)