ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1505.003×

13 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
CampaignFrostyGoop Incident

FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence.

T1505.003
Web Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access.

T1505.003
Web Shell
CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

T1505.003
Web Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

T1505.003
Web Shell
CampaignC0032

During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers.

T1505.003
Web Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism.

T1505.003
Web Shell
CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

T1505.003
Web Shell
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity.

T1505.003
Web Shell
CampaignOperation Wocao

During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement.

T1505.003
Web Shell
CampaignLeviathan Australian Intrusions

Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions.

T1505.003
Web Shell
CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

T1505.003
Web Shell
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.