Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity. |
| T1505.003 Web Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement. |
| T1505.003 Web Shell |
CampaignLeviathan Australian Intrusions | Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions. |
| T1505.003 Web Shell |
CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| T1505.003 Web Shell |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server. |
| T1505.003 Web Shell |
GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1505.003 Web Shell |
GroupGALLIUM | GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration. |
| T1505.003 Web Shell |
GroupKimsuky | Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code. |
| T1505.003 Web Shell |
GroupVolt Typhoon | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments. |
| T1505.003 Web Shell |
GroupDragonfly | Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files. |
| T1505.003 Web Shell |
GroupAPT32 | APT32 has used Web shells to maintain access to victim websites. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1505.003 Web Shell |
GroupSandworm Team | Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks. |
| T1505.003 Web Shell |
GroupCURIUM | CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks. |
| T1505.003 Web Shell |
GroupMustang Panda | Mustang Panda has used China Chopper web shells to maintain access to victims’ environments. |
| T1505.003 Web Shell |
GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| T1505.003 Web Shell |
GroupMoses Staff | Moses Staff has dropped a web shell onto a compromised system. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1505.003 Web Shell |
GroupTropic Trooper | Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1505.003 Web Shell |
GroupMedusa Group | Medusa Group has utilized webshells to an exploited Microsoft Exchange Server. |
| T1505.003 Web Shell |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system. |
| T1505.003 Web Shell |
GroupDeep Panda | Deep Panda uses Web shells on publicly accessible Web servers to access victim networks. |
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1505.003 Web Shell |
GroupVolatile Cedar | Volatile Cedar can inject web shell code into a server. |
| T1505.003 Web Shell |
GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| T1505.003 Web Shell |
GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| T1505.003 Web Shell |
GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| T1505.003 Web Shell |
GroupFox Kitten | Fox Kitten has installed web shells on compromised hosts to maintain access. |
| T1505.003 Web Shell |
GroupTonto Team | Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
| T1505.003 Web Shell |
GroupThreat Group-3390 | Threat Group-3390 has used a variety of Web shells. |
| T1505.003 Web Shell |
GroupFIN13 | FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server. |
| T1505.003 Web Shell |
MalwareSEASHARPEE | SEASHARPEE is a Web shell. |
| T1505.003 Web Shell |
MalwarereGeorg | reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1505.003 Web Shell |
MalwareBUSHWALK | BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| T1505.003 Web Shell |
MalwareP.A.S. Webshell | P.A.S. Webshell can gain remote access and execution on target web servers. |
| T1505.003 Web Shell |
MalwareGLASSTOKEN | GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareASPXSpy | ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS). |
| T1505.003 Web Shell |
MalwareChina Chopper | China Chopper's server component is a Web Shell payload. |
| T1505.003 Web Shell |
MalwareSnappyTCP | SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes. |
| T1505.003 Web Shell |
MalwareLIGHTWIRE | LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareLine Runner | Line Runner is a persistent Lua-based web shell. |
| T1505.003 Web Shell |
MalwareRAPIDPULSE | RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device. |
| T1505.003 Web Shell |
MalwarePHPsert | PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers. |
| T1505.003 Web Shell |
MalwarePULSECHECK | PULSECHECK is a web shell that can enable command execution on compromised servers. |
| T1505.003 Web Shell |
MalwareOwaAuth | OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.