SHELLSTORM is a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on over 1.4 million domains. The access is used to deliver SNOWLIGHT dropper and VShell backdoor, assessed to be the work of a Chinese or Chinese-speaking threat actor.