WP-SHELLSTORM: 25K Sites Hit in Campaign

WP-SHELLSTORM: 25K Sites Hit in Campaign reveals a massive website hacking operation that has compromised over 25,000 WordPress sites. The attack exploited vulnerable websites to install webshells, giving hackers persistent control. An exposed WP-SHELLSTORM server uncovered tools, logs, cloud credentials, and thousands of webshells used in this large-scale campaign, as reported by TechRepublic.

The server contained detailed records of infected sites, allowing security researchers to trace the campaign’s scope. It appears the hackers used automated scripts to scan for weaknesses like outdated plugins and weak passwords. Once inside, they uploaded webshells, which act as backdoors for further attacks, including data theft or using the site for malicious redirects.

Due to the WP-SHELLSTORM threat, any site administrator should immediately check logs for unusual files or connection attempts. The leaked cloud credentials indicate the attackers could access broader infrastructure, making this a critical security event. This campaign targets sites globally, highlighting the importance of regular updates and strong login protections.

In conclusion, this WP-SHELLSTORM incident serves as a stark reminder for all website owners to prioritize security. With over 25,000 sites already compromised, proactive measures like scanning for webshells and patching vulnerabilities are essential to avoid becoming part of such cyberattacks.

Leave a Reply

Your email address will not be published. Required fields are marked *