INTEL_REPORT
The Hacker News · published 7/10/2026, 11:30:02 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as …
https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
sha256:15bd69214631e967e62a62fbfba759699688a0361e7fd8c2c12f228a69076e8e
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| nacos.core.auth.enabled |
| Open → |
| domain | bd.php | Open → |
| domain | wp-log.php | Open → |
| domain | xs.xxooonline.eu.cc | Open → |
| cve | CVE-2026-3844 | Open → |
| cve | CVE-2021-29441 | Open → |
| cve | CVE-2026-3300 | Open → |
| cve | CVE-2026-48907 | Open → |
| cve | CVE-2026-1969 | Open → |
| cve | CVE-2020-36847 | Open → |
| cve | CVE-2026-6433 | Open → |
| cve | CVE-2025-7443 | Open → |
| cve | CVE-2026-0740 | Open → |
| cve | CVE-2025-12057 | Open → |
| cve | CVE-2025-7852 | Open → |
| cve | CVE-2020-25213 | Open → |
| cve | CVE-2025-34085 | Open → |