Threat Actor

WP-SHELLSTORM

Properties

summary
A cybercrime crew operating under the WP-SHELLSTORM name left an exposed server revealing tools, activity logs, and target lists naming over 1.4 million WordPress websites.
first_seen
2026-07-13T04:00:19.693199+00:00
last_seen
2026-07-13T04:00:19.693199+00:00
created_at
2026-07-13T04:00:19.693199+00:00
mention_count
1
evidence_url
https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
target
WordPress sites
provenance
news-scan
scan_confidence
0.65
suspected_origin
unknown
status
pending

Explore this actor's full graph with Ninja Signal

WP-SHELLSTORM — Threat Actor Profile — Ninja Signal | Ninja Signal