T1100 - Web Shell - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 13, 2025
Last Seen
December 11, 2025

T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network.

T1100 - Web Shell is a mitre_attack tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity December 11, 2025.

Overview

T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network. Key traits include lightweight, server-side scripts (e.g., PHP, ASP, JSP) or binaries, covert command and control, and post-exploitation use to remotely control assets. It remains significant due to its effectiveness for long-term access and easy integration into broader intrusion chains.

Related Threat Clusters

  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems

    An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…

    16 articles · Updated November 18, 2025
  • Chinese Hackers Linked to Cisco Training in Salt Typhoon Attacks

    Two former Cisco Networking Academy trainees, Qiu Daibing and Yu Yang, have been identified as potential orchestrators of the Salt Typhoon cyber espionage campaign that targeted critical networks in 2024. The attackers…

    2 articles · Updated December 11, 2025

Recent Intelligence Reports

  • Chinese hackers exploited Cisco training to help build Salt Typhoon attacks — Sdxcentral · December 11, 2025
  • Zero-day attacks against Cisco ISE, Citrix NetScaler observed — Scworld · November 13, 2025

Frequently asked questions

What is T1100 - Web Shell?

T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network.

Is T1100 - Web Shell still active?

The most recent intelligence report mentioning T1100 - Web Shell on ThreatCluster is dated December 11, 2025. Activity was first observed November 13, 2025, giving a tracked span from then to December 11, 2025.

What is T1100 - Web Shell associated with?

Across ThreatCluster reporting, T1100 - Web Shell most frequently co-occurs with Salt Typhoon, Malware, Zero-day Exploit, Citrix Bleed 2, Australia, among 12 tracked related entities.

What are the latest developments involving T1100 - Web Shell?

The most significant recent cluster is “FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation” (100 articles · Updated November 15, 2025). T1100 - Web Shell appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1100 - Web Shell?

T1100 - Web Shell appears in 2 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown