Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
A suspected Chinese state group linked by Sysdig to the SNOWLIGHT-to-VShell toolchain in April 2025. The same tools were used by WP-SHELLSTORM,…
A stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with kernel threads. Used by WP-SHELLSTORM for remote access,…
A dropper used by WP-SHELLSTORM to install the VShell backdoor. Previously linked to UNC5174 by Sysdig in April 2025.
A security company that linked the SNOWLIGHT-to-VShell toolchain to UNC5174 in April 2025.