Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
CampaignFrostyGoop Incident | FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1505.003 Web Shell |
CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| T1505.003 Web Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| T1505.003 Web Shell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| T1505.003 Web Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism. |
| T1505.003 Web Shell |
CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| T1505.003 Web Shell |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity. |
| T1505.003 Web Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement. |
| T1505.003 Web Shell |
CampaignLeviathan Australian Intrusions | Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions. |
| T1505.003 Web Shell |
CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| T1505.003 Web Shell |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.