Campaigns
WP-SHELLSTORM - WordPress Mass Exploitation Operation

WP-SHELLSTORM - WordPress Mass Exploitation Operation

WordPressJoomlaPrestaShopCraft CMSApache NacosSNOWLIGHTWebshell Access BrokerageWP-SHELLSTORMWebshell Access Brokerage (WABO)
Financially motivated, China-linked webshell access brokerage operation (WABO) running two parallel campaigns from a single, fully exposed operations server (137.175.93.126). Campaign A weaponizes 27 CVEs across WordPress, Joomla, PrestaShop, Craft CMS, MetInfo and MaxSite, queuing 1.4M+ domains via FOFA recon and confirming 5,700+ live webshells, backed by a SNOWLIGHT-stager, VShell C2 delivery chain with kworker-process masquerading. Campaign B is a one-month-earlier, high-precision breach of enterprise Java infrastructure - Apache Nacos, XXL-Job, and Spring Boot - compromising 11 victims and exfiltrating 613 configuration files including cloud and payment-system keys.

Indicators of Compromise

xs.xxooonline.eu.cc

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediation / Detection

MITRE ATT&CK mapping for the WP-SHELLSTORM kill chain, from FOFA-driven reconnaissance through persistent, disguised VShell implantation, and the parallel Nacos/XXL-Job/Spring Boot intrusion branch.

Technique ID

Technique Name

Detection ID

Detection Name

Recommended Detection Action

T1596

Search Open Technical Databases (FOFA/Shodan Recon)

D-01

Mass reconnaissance sweep of CMS fingerprints

Baseline and alert on unusually broad, low-interaction scanning traffic hitting version-fingerprint endpoints (wp-json, readme.html, /administrator/manifests) at scale.

T1190

Exploit Public-Facing Application

D-02

Weaponized CVE exploitation across CMS plugins

Deploy virtual patching / WAF rules for the 27 listed CVEs; alert on POST requests to plugin upload/import endpoints outside admin sessions.

T1505.003

Server Software Component: Web Shell

D-03

Webshell filename/pattern upload

File-integrity monitoring on web roots for the filename patterns and directory paths listed in Mitigation; alert on any new .php file in cache/upload directories.

T1071.001

Application Layer Protocol: Web Protocols

D-04

SNOWLIGHT stager / VShell WebSocket C2

Inspect outbound WebSocket upgrades to unfamiliar domains from web-server hosts; flag connections to xs.xxooonline.eu.cc or its resolved IPs.

T1036.004

Masquerading: Masquerade Task or Service

D-05

VShell implant disguised as kworker

Run the process-anomaly check (ps aux | grep kworker, verify /proc/{pid}/exe) on all Linux hosts; alert on any kworker-named process resolving to a non-kernel binary path.

T1583.001/.004

Acquire Infrastructure: Domains/Server

D-06

Disposable subdomain / staging server use

Flag DNS resolutions to free/disposable subdomain providers (e.g., eu.cc) combined with newly observed hosting ASNs.

T1136

Create Account

D-07

Unauthorized webshell-based account/user creation

Monitor CMS admin-user creation events outside change windows correlated with webshell file-access logs.

T1210

Exploitation of Remote Services

D-08

Apache Nacos authentication bypass (CVE-2021-29441)

Alert on GET /nacos/v1/cs/configs and GET /nacos/v1/auth/users requests carrying User-Agent: Nacos-Server from non-internal sources.

T1210

Exploitation of Remote Services

D-09

XXL-Job unauthenticated RCE

Monitor XXL-Job admin panel exposure; alert on repeated POST /xxl-job-admin/login attempts with iterating password values (brute force).

T1552.005

Unsecured Credentials: Cloud Instance Metadata / App Config

D-10

Spring Boot Actuator heap-dump credential theft

Alert on GET /actuator/heapdump, /actuator/env, and /actuator/beans from external sources; disable these endpoints in production.

T1210 / T1570

Lateral Movement via Nacos-to-XXL-Job Trust

D-11

Config-server pivot to executor RCE

Segment Nacos config servers from XXL-Job executor networks; alert on new executor registrations following a Nacos compromise indicator.

T1560 / T1041

Archive / Exfiltrate Collected Data

D-12

Bulk configuration file / archive exfiltration

Alert on large outbound transfers of .tar.gz/.zip archives from configuration-management hosts to unfamiliar external IPs.

T1070.002

Indicator Removal: Clear Linux/Mac System Logs

D-13

Operator self-deletion of server logs post-exposure

Monitor for gaps or truncation in httpd/access logs and bash history immediately following unusual inbound access from research/monitoring IP ranges.


Observed Countries250

AD (793)
AE (791)
AF (909)
AG (899)
AI (41)
AL (194)
AM (381)
AO (705)
AQ (85)
AR (118)
AS (569)
AT (847)
AU (393)
AW (173)
AX (280)
AZ (290)
BA (392)
BB (79)
BD (576)
BE (805)
BF (93)
BG (372)
BH (399)
BI (11)
BJ (554)
BL (177)
BM (553)
BN (511)
BO (120)
BQ (573)
BR (159)
BS (20)
BT (914)
BV (978)
BW (987)
BY (726)
BZ (317)
CA (77)
CC (526)
CD (607)
CF (88)
CG (342)
CH (537)
CI (592)
CK (215)
CL (263)
CM (167)
CN (159)
CO (520)
CR (418)
CU (733)
CV (8)
CW (144)
CX (418)
CY (404)
CZ (441)
DE (847)
DJ (398)
DK (40)
DM (280)
DO (340)
DZ (626)
EC (24)
EE (87)
EG (642)
EH (78)
ER (329)
ES (225)
ET (318)
FI (904)
FJ (467)
FK (958)
FM (768)
FO (883)
FR (639)
GA (955)
GB (129)
GD (897)
GE (262)
GF (946)
GG (654)
GH (484)
GI (341)
GL (204)
GM (552)
GN (90)
GP (242)
GQ (794)
GR (429)
GS (678)
GT (669)
GU (343)
GW (701)
GY (138)
HK (555)
HM (999)
HN (987)
HR (533)
HT (656)
HU (153)
ID (395)
IE (141)
IL (34)
IM (61)
IN (954)
IO (991)
IQ (991)
IR (626)
IS (221)
IT (859)
JE (401)
JM (763)
JO (245)
JP (615)
KE (169)
KG (301)
KH (941)
KI (579)
KM (202)
KN (487)
KP (852)
KR (769)
KW (892)
KY (183)
KZ (638)
LA (371)
LB (575)
LC (808)
LI (540)
LK (222)
LR (181)
LS (798)
LT (82)
LU (515)
LV (85)
LY (384)
MA (859)
MC (744)
MD (948)
ME (217)
MF (54)
MG (647)
MH (359)
MK (559)
ML (61)
MM (473)
MN (707)
MO (817)
MP (936)
MQ (115)
MR (761)
MS (615)
MT (394)
MU (465)
MV (964)
MW (838)
MX (717)
MY (61)
MZ (913)
NA (508)
NC (61)
NE (285)
NF (409)
NG (138)
NI (989)
NL (415)
NO (544)
NP (543)
NR (60)
NU (620)
NZ (133)
OM (80)
PA (448)
PE (293)
PF (925)
PG (845)
PH (455)
PK (120)
PL (505)
PM (294)
PN (174)
PR (911)
PS (625)
PT (420)
PW (492)
PY (923)
QA (64)
RE (384)
RO (939)
RS (180)
RU (487)
RW (459)
SA (891)
SB (88)
SC (366)
SD (182)
SE (426)
SG (161)
SH (899)
SI (638)
SJ (181)
SK (958)
SL (831)
SM (271)
SN (627)
SO (113)
SR (571)
SS (221)
ST (146)
SV (886)
SX (818)
SY (59)
SZ (718)
TC (773)
TD (572)
TF (623)
TG (985)
TH (235)
TJ (909)
TK (217)
TL (641)
TM (225)
TN (918)
TO (880)
TR (134)
TT (935)
TV (958)
TW (653)
TZ (264)
UA (712)
UG (861)
UM (689)
US (153)
UY (311)
UZ (332)
VA (172)
VC (691)
VE (693)
VG (541)
VI (88)
VN (100)
VU (149)
WF (696)
WS (698)
XK (609)
YE (5)
YT (20)
ZA (285)
ZM (465)
ZW (112)