{
  "Event": {
    "analysis": "1",
    "date": "2026-07-09",
    "extends_uuid": "",
    "info": "[Threat Intel] How WP-SHELLSTORM Exposed 1.4M WordPress Sites",
    "protected": false,
    "publish_timestamp": "1784437654",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1784437654",
    "uuid": "846c2e85-15fd-4cf8-9ab9-8487701419de",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#a4da83",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cron - T1053.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#fe1ef0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Shell - T1505.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d11f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b0fe1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerade Task or Service - T1036.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7628f7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Unix Shell - T1059.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#30cc3b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e1e63b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL Side-Loading - T1574.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120046",
        "local": false,
        "name": "rectifyq:sub-category=\"infra-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#ad61df",
        "local": false,
        "name": "misp-galaxy:country=\"singapore\"",
        "relationship_type": ""
      },
      {
        "colour": "#1237d4",
        "local": false,
        "name": "misp-galaxy:country=\"taiwan\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"SNOWLIGHT\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Vshell\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:operating-system=\"Linux\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"WordPress\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "link",
        "uuid": "55c30300-9fdd-4c53-a0b6-a8161cb584ad",
        "value": "https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "text",
        "uuid": "a1835820-f522-4025-87bc-400380ecdccc",
        "value": "A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "text",
        "uuid": "30109a18-a2ea-468b-baa3-0770ef7998b3",
        "value": "Name: How WP-SHELLSTORM Exposed 1.4M WordPress Sites\nAuthor: AlienVault\nAdversary: WP-SHELLSTORM\nTags: [\"wordpress\", \"botnet\", \"vshell\", \"godzilla\", \"webshell\", \"access-brokerage\"]\nTgtd countries: []\nMlwr families: [\"SNOWLIGHT\", \"VShell\", \"BestShell\", \"Godzilla\"]\nAttack_ids: [\"T1059.007\", \"T1053.003\", \"T1082\", \"T1005\", \"T1140\", \"T1190\", \"T1055\", \"T1505.003\", \"T1552.004\", \"T1070.001\", \"T1083\", \"T1036.004\", \"T1552.001\", \"T1059.004\", \"T1027\", \"T1070.004\", \"T1071.001\", \"T1574.002\", \"T1105\", \"T1078.004\"]\nIndustries: [\"Finance\", \"Retail\", \"Technology\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "bc37050e-2dcd-497e-b117-74d5a2cc1c72",
        "value": "WP-SHELLSTORM"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "d2cb741a-23af-4189-82b9-1ce0442b517e",
        "value": "CVE-2020-25213"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "0bbc6b9c-bf98-4357-b84b-a109313dd379",
        "value": "CVE-2021-29441"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "b58d91ae-25b6-4294-be5e-2ce8655098f7",
        "value": "CVE-2026-1969"
      },
      {
        "category": "Network activity",
        "comment": "IOC-description:CC=SG ASN=ASNone",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434605",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "f4035ae3-2623-4d71-8eee-8ef2f381589d",
        "value": "43.108.17.80",
        "Tag": [
          {
            "colour": "#836891",
            "local": false,
            "name": "asn:asn=\"45102\"",
            "relationship_type": ""
          },
          {
            "colour": "#692b04",
            "local": false,
            "name": "asn:as-owner=\"ALIBABA-CN-NET Alibaba US Technology Co., Ltd.\"",
            "relationship_type": ""
          },
          {
            "colour": "#9256df",
            "local": false,
            "name": "asn:as-country=\"CN\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"china\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "8d134d86-9f8d-4f08-9bb2-bdfc6fd19803",
        "value": "CVE-2026-0740"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "a21098cb-c1dc-4756-bda8-44e62f22ee19",
        "value": "CVE-2026-3844"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "6ed14772-65e8-4596-9e65-701043896d81",
        "value": "CVE-2026-6433"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "f7b59dc7-f79f-44e2-a93c-68f6f7f43617",
        "value": "CVE-2026-48907"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434626",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "0fb8563d-f0ad-47f5-99ee-da3eed30078a",
        "value": "137.175.93.126",
        "Tag": [
          {
            "colour": "#e7b1b4",
            "local": false,
            "name": "asn:asn=\"54600\"",
            "relationship_type": ""
          },
          {
            "colour": "#6fa6ce",
            "local": false,
            "name": "asn:as-owner=\"PEG-SV\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "17bf9b28-0ac4-416d-854d-9572ad3c12cd",
        "value": "CVE-2025-12057"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "b2d3ab2e-3306-4b2b-9e47-12a5f717a2ad",
        "value": "CVE-2025-34085"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "36b60e08-8411-4716-a474-4dff452dbf72",
        "value": "CVE-2025-7443"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "a24889c3-dbe7-4279-b379-1e0d78c21093",
        "value": "CVE-2025-7852"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 19/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434424",
        "to_ids": true,
        "type": "sha256",
        "uuid": "ca664d5b-77e6-4b62-b2e8-0a89c60a3009",
        "value": "84f7e396a48913851a10cc78c5cc22a25634564abd0694465236d2f365e2bdee",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "2b2a0d9c-1b2a-427e-9a71-b99a1ea6e656",
        "value": "CVE-2026-50746"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783940427",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "9218012d-0f99-4601-8f80-6a0096cf0ec5",
        "value": "CVE-2026-40138"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434647",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "eacc1ca4-267a-45b0-b012-bb95047651d3",
        "value": "113.196.56.150",
        "Tag": [
          {
            "colour": "#44363e",
            "local": false,
            "name": "asn:asn=\"9919\"",
            "relationship_type": ""
          },
          {
            "colour": "#82d071",
            "local": false,
            "name": "asn:as-owner=\"NCIC-TW New Century InfoComm Tech Co., Ltd.\"",
            "relationship_type": ""
          },
          {
            "colour": "#9053fd",
            "local": false,
            "name": "asn:as-country=\"TW\"",
            "relationship_type": ""
          },
          {
            "colour": "#1237d4",
            "local": false,
            "name": "misp-galaxy:country=\"taiwan\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434668",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "89c1bebe-a0e0-45c4-afa2-ea1d9318dbc2",
        "value": "113.196.59.51",
        "Tag": [
          {
            "colour": "#44363e",
            "local": false,
            "name": "asn:asn=\"9919\"",
            "relationship_type": ""
          },
          {
            "colour": "#82d071",
            "local": false,
            "name": "asn:as-owner=\"NCIC-TW New Century InfoComm Tech Co., Ltd.\"",
            "relationship_type": ""
          },
          {
            "colour": "#9053fd",
            "local": false,
            "name": "asn:as-country=\"TW\"",
            "relationship_type": ""
          },
          {
            "colour": "#1237d4",
            "local": false,
            "name": "misp-galaxy:country=\"taiwan\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784434689",
        "to_ids": true,
        "type": "hostname",
        "uuid": "d3cd7b02-1cd4-4288-a43d-88a6006dd5ce",
        "value": "xs.xxooonline.eu.cc",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}