ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity.

T1505.003
Web Shell
CampaignOperation Wocao

During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement.

T1505.003
Web Shell
CampaignLeviathan Australian Intrusions

Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions.

T1505.003
Web Shell
CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

T1505.003
Web Shell
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server.

T1505.003
Web Shell
GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1505.003
Web Shell
GroupGALLIUM

GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration.

T1505.003
Web Shell
GroupKimsuky

Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code.

T1505.003
Web Shell
GroupVolt Typhoon

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.

T1505.003
Web Shell
GroupDragonfly

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.

T1505.003
Web Shell
GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1505.003
Web Shell
GroupSandworm Team

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.

T1505.003
Web Shell
GroupCURIUM

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

T1505.003
Web Shell
GroupMustang Panda

Mustang Panda has used China Chopper web shells to maintain access to victims’ environments.

T1505.003
Web Shell
GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

T1505.003
Web Shell
GroupMoses Staff

Moses Staff has dropped a web shell onto a compromised system.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1505.003
Web Shell
GroupTropic Trooper

Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1505.003
Web Shell
GroupMedusa Group

Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.

T1505.003
Web Shell
GroupBackdoorDiplomacy

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

T1505.003
Web Shell
GroupDeep Panda

Deep Panda uses Web shells on publicly accessible Web servers to access victim networks.

T1505.003
Web Shell
GroupEmber Bear

Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples.

T1505.003
Web Shell
GroupVolatile Cedar

Volatile Cedar can inject web shell code into a server.

T1505.003
Web Shell
GroupAgrius

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.

T1505.003
Web Shell
GroupAPT28

APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.

T1505.003
Web Shell
GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

T1505.003
Web Shell
GroupFox Kitten

Fox Kitten has installed web shells on compromised hosts to maintain access.

T1505.003
Web Shell
GroupTonto Team

Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server.

T1505.003
Web Shell
GroupMagic Hound

Magic Hound has used multiple web shells to gain execution.

T1505.003
Web Shell
GroupThreat Group-3390

Threat Group-3390 has used a variety of Web shells.

T1505.003
Web Shell
GroupFIN13

FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server.

T1505.003
Web Shell
MalwareSEASHARPEE

SEASHARPEE is a Web shell.

T1505.003
Web Shell
MalwarereGeorg

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1505.003
Web Shell
MalwareBUSHWALK

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

T1505.003
Web Shell
MalwareP.A.S. Webshell

P.A.S. Webshell can gain remote access and execution on target web servers.

T1505.003
Web Shell
MalwareGLASSTOKEN

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareASPXSpy

ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).

T1505.003
Web Shell
MalwareChina Chopper

China Chopper's server component is a Web Shell payload.

T1505.003
Web Shell
MalwareSnappyTCP

SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes.

T1505.003
Web Shell
MalwareLIGHTWIRE

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareLine Runner

Line Runner is a persistent Lua-based web shell.

T1505.003
Web Shell
MalwareRAPIDPULSE

RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device.

T1505.003
Web Shell
MalwarePHPsert

PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers.

T1505.003
Web Shell
MalwarePULSECHECK

PULSECHECK is a web shell that can enable command execution on compromised servers.

T1505.003
Web Shell
MalwareOwaAuth

OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.