Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1505.003 Web Shell |
GroupGALLIUM | GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration. |
| T1505.003 Web Shell |
GroupKimsuky | Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code. |
| T1505.003 Web Shell |
GroupVolt Typhoon | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments. |
| T1505.003 Web Shell |
GroupDragonfly | Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files. |
| T1505.003 Web Shell |
GroupAPT32 | APT32 has used Web shells to maintain access to victim websites. |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1505.003 Web Shell |
GroupSandworm Team | Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks. |
| T1505.003 Web Shell |
GroupCURIUM | CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks. |
| T1505.003 Web Shell |
GroupMustang Panda | Mustang Panda has used China Chopper web shells to maintain access to victims’ environments. |
| T1505.003 Web Shell |
GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| T1505.003 Web Shell |
GroupMoses Staff | Moses Staff has dropped a web shell onto a compromised system. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1505.003 Web Shell |
GroupTropic Trooper | Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1505.003 Web Shell |
GroupMedusa Group | Medusa Group has utilized webshells to an exploited Microsoft Exchange Server. |
| T1505.003 Web Shell |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system. |
| T1505.003 Web Shell |
GroupDeep Panda | Deep Panda uses Web shells on publicly accessible Web servers to access victim networks. |
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1505.003 Web Shell |
GroupVolatile Cedar | Volatile Cedar can inject web shell code into a server. |
| T1505.003 Web Shell |
GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| T1505.003 Web Shell |
GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| T1505.003 Web Shell |
GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| T1505.003 Web Shell |
GroupFox Kitten | Fox Kitten has installed web shells on compromised hosts to maintain access. |
| T1505.003 Web Shell |
GroupTonto Team | Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
| T1505.003 Web Shell |
GroupThreat Group-3390 | Threat Group-3390 has used a variety of Web shells. |
| T1505.003 Web Shell |
GroupFIN13 | FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.