
WP BOTNET MASTER Threat Campaign
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Patch or remove FS Registration Password ≤ 1.0.1 (CVE-2025-15001); audit all installed plugins for known-vulnerable versions.
Force-rotate all WordPress admin, FTP/SFTP, and cPanel credentials; enforce strong unique passwords and MFA on wp-admin.
Remove the unauthorized admin user “xilang” and audit wp_users for any other unrecognized accounts.
Hunt and purge Ghost Protocol database payloads: check wp_options for transient_sys_pma_check, _cache_vx, and _idx_core.
Remove webshell files masquerading as WordPress core classes (class-wp-hook.php, class-wp-widget.php, class-wp-meta.php, class-wp-locale.php, class-wp-theme.php) and randomly-named plugin folders under wp-content/plugins/.
Restore security plugins renamed to *_killed_* (Wordfence, Sucuri, iThemes); reinstall from official source and verify integrity.
Block the master C2 (217.216.72.31) and known worker IPs at firewall/WAF; block outbound to the identified Telegram bot token and the GitHub payload repos.
Restore from backups predating 3 July 2026 for any site where compromise is confirmed and clean recovery is uncertain.
Rotate cPanel API tokens and hosting-account credentials targeted by the shell's built-in token-theft feature.
File coordinated disclosure with WPScan & Wordfence (dual-use of researcher/bounty programs), Telegram (ToS violations — @Real_King_Engine, @wpxploit, @ISAL_Framework, @cliproot/@cliproots), GitHub (zeroxipinder repos used as live C2), Google Cloud (published GCP lab blueprint reuse), and relevant AI vendors' trust-and-safety teams (claimed use of Claude/Gemini to generate exploit code).