Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
DEWMODE is a web shell deployed by Clop after exploiting Accellion FTA vulnerabilities. It provides remote access and data exfiltration capabilities.
LEMURLOOT is a web shell used by Clop in MOVEit Transfer attacks, enabling credential theft and data exfiltration.
RelayShell is a previously undocumented PHP web shell used by Lazarus Group to compromise Roundcube webmail servers. It enables command and response…
emer-run.php is a PHP web shell installed via a fake plugin in the BdThemes supply chain attack, enabling remote code execution on…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
w2.js is a JavaScript payload used in the BdThemes supply chain attack. It contacts a C2 server, creates rogue admin accounts, installs…
Russian cybersecurity vendor Kaspersky has uncovered a new attack campaign by the threat actor known as Head Mare, targeting unpatched TrueConf videoconferencing…
KNUCKLEBALL is a Python script deployed by threat actors to launch Suo5, an open-source HTTP proxy, and a Behinder-like web shell named…
ORANGETAIL is a Behinder-like custom Java web shell used by threat actors to maintain persistent access on compromised SonicWall SMA 1000 appliances.…