#WebShells
free webshells you say
August 11, 2024 at 9:54 PM
Find someone who loves you as much as Steven Adair loves webshells
November 22, 2024 at 5:23 PM
We have started to report webshells (or other artifacts) found on Ivanti EPMM devices, likely compromised via CVE-2026-1281. 56 IPs found on 2026-02-06

Data in shadowserver.org/what-we-do/n...

Tree Map view: dashboard.shadowserver.org/statistics/c...

Thank you to the KSA NCA for the heads up!
February 7, 2026 at 4:22 PM
The Dutch cybersecurity agency has released a script to detect webshells typically installed by attackers exploiting the CitrixBleed2 vulnerability in Citrix NetScaler appliances

github.com/NCSC-NL/citr...
GitHub - NCSC-NL/citrix-2025
Contribute to NCSC-NL/citrix-2025 development by creating an account on GitHub.
github.com
July 27, 2025 at 2:18 PM
Webshells Remain Popular https://isc.sans.edu/diary/33096
June 22, 2026 at 2:10 PM
David Ottenheimer (flyingpenguin over at infosec.exchange) wrote about the #history of webshells.
www.flyingpenguin.com/the-history-...
The History of Webshell | flyingpenguin
www.flyingpenguin.com
August 29, 2026 at 9:03 PM
A Chinese APT left a server exposed and leaked its exploits

-Fortinet firewall and VPN exploit scripts
-A PHP-based webshell
-Network reconnaissance scripts

hunt.io/blog/keyplug...
KeyPlug Server Exposes Fortinet Exploits & Webshell Activity Targeting a Major Japanese Company
Briefly exposed KeyPlug infrastructure revealed Fortinet exploits, encrypted webshells, and recon scripts targeting Shiseido, a major Japanese enterprise. Learn more..
hunt.io
April 20, 2025 at 12:14 PM
Question for tech Bluesky and #skystorians or digital humanities people with an interest in cybersecurity, has anyone ever written an early history of webshells? It’s yet another “basic” thing that I can’t find any real written account of.

Please reskeet for reach.
Man Studying a Book for Knowledge
ALT: Man Studying a Book for Knowledge
static.klipy.com
August 21, 2026 at 11:28 PM
Chasse à la menace sur Linux, utiliser Sysmon et auditd et détecter des webshells.
-> pberba.github.io/sec...
April 8, 2024 at 12:30 PM
Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create rogue users.
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create rogue users.
www.bleepingcomputer.com
December 4, 2025 at 11:05 PM
I think it's really considerate of WordPress attackers that they never attempt novel exploitation techniques. Keep rockin' the same webshells forever, boys.
July 21, 2026 at 5:21 PM
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug www.infosecurity-magazine.com/news/woocomm...
PHP Webshell Campaign Targets WordPress Through WooCommerce Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
www.infosecurity-magazine.com
September 21, 2026 at 4:42 PM
Thanks to collaboration with the Canadian Centre for Cyber Security we can share more comprehensive information on FreePBX instances running webshells, with still over 900 IPs seen compromised.

Dashboard Victim overview (Tree map) dashboard.shadowserver.org/statistics/c...
February 24, 2026 at 7:19 PM
The Microsoft Exchange exploitation campaign started by Hafnium is one of my favorites for many reasons, not the least of which is that everyone got so excited about wiping out the slapdash contractor webshells that nobody bothered to ask what happened to the original Hafnium actor
November 23, 2024 at 2:53 PM
F5 has reclassified a BIG-IP APM denial-of-service (DoS) vulnerability as a critical-severity remote code execution (RCE) flaw, warning that attackers are exploiting it to deploy webshells on unpatched devices.
Hackers now exploit critical F5 BIG-IP flaw in attacks, patch now
F5 has reclassified a BIG-IP APM denial-of-service (DoS) vulnerability as a critical-severity remote code execution (RCE) flaw, warning that attackers are exploiting it to deploy webshells on unpatched devices.
www.bleepingcomputer.com
March 30, 2026 at 10:59 AM
Attention! We are sharing SAP NetWeaver instances vulnerable to CVE-2025-31324 unauth upload (CVSS 10.0). 454 IPs found vulnerable on 2025-04-26. If you receive an alert from us, make sure to check for signs of compromise (incl. webshells).

World Map: dashboard.shadowserver.org/statistics/c...
April 27, 2025 at 4:31 PM
"We are seeing ongoing attack campaigns exploiting Citrix ADC/Gateway CVE-2023-3519. Make sure to check your instances for webshells."
Seeing ongoing exploitation campaigns for Citrix ADC/Gateway CVE-2023-3519. Make sure to check your instances for webshells.

We are aware of widespread exploitation happening July 20th already. If you did not patch by then please assume compromise.
August 1, 2023 at 11:06 AM
🤖 CVE-2026-87902: critical WordPress flaw actively exploited. Attackers write files to disk that execute shell commands on access — patch and audit webroots for webshells.

https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
September 24, 2026 at 5:35 AM
AI being the Chinese character for "love," and love being the emotion that Chinese operators feel towards webshells and cracked Cobalt Strike?

Then yes. They're using "AI."
September 20, 2023 at 9:05 PM
I notice that the person you linked also wrote about Coldfusion webshells (separately).
It's crazy all this talk of webshells and not touched on coldfusion which felt like it was constantly getting owned for a decade or more.
It was a big part of LizardSquad botnets.
Webshells is a huuuge topic.
August 30, 2026 at 10:15 AM