Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The hacking tools, activity logs, and target lists identifying over 1.4 million websites were all exposed when a cybercrime group left one of its own servers accessible on the internet for three weeks.
The released files demonstrated to researchers how a mass site-hacking operation operates from the inside, even if many fewer were really compromised.
The operation, which is now being monitored as WP-SHELLSTORM, is what SOCRadar refers to as a webshell access brokerage: a team that breaches websites on a large scale, installs a covert backdoor (a "webshell") on each, then bundles that access for sales.
WordPress websites with outdated plugins had the most engagement. The Breeze caching plugin and Joomla's JCE editor were the two issues that mattered most whether you use WordPress ...

