WP-SHELLSTORM: Exposed Server Reveals Mass WordPress Backdoor Operation
A cybercrime crew left its server open for 22 days, exposing a massive operation that backdoored thousands of WordPress sites using 27 CVEs, including CVE-2026-3844 in Breeze caching plugin.

h2>Overview/h2h2Discovery/h2. gridpOn June 11, 2026, SOCRadar's Threat Intelligence Team spotted an open directory at 137.175.93[.]126 with no authentication. Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, bash history, and C2 formation. The exposure lasted 22 days due to a forgotten Python SimpleHTTerver instance against/thep>h2Key Vulnerabilities/h. While 1.4 million domains were targeted, actual compromises were lower: Ctrl-Alt-Intel found 25,195 confirmed sites, while SOCRadar counted 5,700+ active webshells. واشتملت العملية أيضاً على حملة أكثر هدوءاً في أيار/مايو 2026 قامت بتصفية 613 ملفاً للتشكيلات من 11 نظاماً عبر تسع شركات، وسرقة وثائق التفويض السحابية، وكلمات مرور قاعدة البيانات، ومفاتيح " Alipay RSA " الخاصة. ويقيّم كل من شركة SoCRadar وCtrl-Alt-Intel بثقة متوسطة إلى عالية بأن المشغل صيني أو صيني، على أساس صيني مبسّط، واستخدام FOFA (يتطلب رقم الهاتف الصيني)، وأداة مثل غودزيلا وفيشل. غير أن الطاقم يعتبر مدفوعاً مالياً وليس مشرفاً على الدولة. إذا قمت بتشغيل ووردبريس أو جوملا، رقعة على الفور: بريز (CVE-2026-3844، ثابتة في 2-4.5)، جومولا JCE (CVE-2026-48907، ثابتة في 2.9.99.5). Also check ThemeREX Addons, simple File List, Custom CSS JS PHP, BerqWP, Ninja Forms, WavePlayer, WPBookit, and WP File Manager. بالنسبة لـ (ناكوس)، رفع مستوى الترقية إلى 2-2-1+ وتمكين التوثيق. هنـت من أجـل الـورقـة بـأنـماط كـ (ب) و أسفل