ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1505.003×

31 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1505.003
Web Shell
GroupGALLIUM

GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration.

T1505.003
Web Shell
GroupKimsuky

Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code.

T1505.003
Web Shell
GroupVolt Typhoon

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.

T1505.003
Web Shell
GroupDragonfly

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.

T1505.003
Web Shell
GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1505.003
Web Shell
GroupSandworm Team

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.

T1505.003
Web Shell
GroupCURIUM

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

T1505.003
Web Shell
GroupMustang Panda

Mustang Panda has used China Chopper web shells to maintain access to victims’ environments.

T1505.003
Web Shell
GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

T1505.003
Web Shell
GroupMoses Staff

Moses Staff has dropped a web shell onto a compromised system.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1505.003
Web Shell
GroupTropic Trooper

Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1505.003
Web Shell
GroupMedusa Group

Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.

T1505.003
Web Shell
GroupBackdoorDiplomacy

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

T1505.003
Web Shell
GroupDeep Panda

Deep Panda uses Web shells on publicly accessible Web servers to access victim networks.

T1505.003
Web Shell
GroupEmber Bear

Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples.

T1505.003
Web Shell
GroupVolatile Cedar

Volatile Cedar can inject web shell code into a server.

T1505.003
Web Shell
GroupAgrius

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.

T1505.003
Web Shell
GroupAPT28

APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.

T1505.003
Web Shell
GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

T1505.003
Web Shell
GroupFox Kitten

Fox Kitten has installed web shells on compromised hosts to maintain access.

T1505.003
Web Shell
GroupTonto Team

Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server.

T1505.003
Web Shell
GroupMagic Hound

Magic Hound has used multiple web shells to gain execution.

T1505.003
Web Shell
GroupThreat Group-3390

Threat Group-3390 has used a variety of Web shells.

T1505.003
Web Shell
GroupFIN13

FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.