Web Shell - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
November 1, 2025
Last Seen
August 21, 2026

Related Threat Clusters

  • UAT-7290 Cyber Espionage Targets South Asian Telecoms

    UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…

    2 articles · Updated January 12, 2026
  • Critical Joomla JCE Vulnerability Under Active Exploitation

    A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…

    33 articles · Updated June 17, 2026
  • Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities

    An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…

    8 articles · Updated November 12, 2025
  • Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors

    The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…

    23 articles · Updated August 8, 2026
  • Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies

    The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and…

    30 articles · Updated August 14, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems

    An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…

    16 articles · Updated November 18, 2025
  • China's Brickstorm Malware Compromises US Critical Networks

    Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…

    10 articles · Updated December 4, 2025
  • Microsoft's .NET RCE Bug Remains Unfixed, Affecting Enterprise Applications

    Security researchers have identified a remote code execution (RCE) vulnerability in the .NET framework that impacts various enterprise applications. Piotr Bazydło from watchTowr presented these findings at Black Hat…

    3 articles · Updated December 10, 2025
  • CISA Flags OpenPLC ScadaBR Vulnerability as Actively Exploited

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the OpenPLC ScadaBR vulnerability, tracked as CVE-2021-26829, to its Known Exploited Vulnerabilities catalog after confirming active…

    2 articles · Updated December 2, 2025

Recent Intelligence Reports

  • Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it — Theregister · August 21, 2026
  • Shell and Philips Confirm Investigation as Cl0p Claimed Data Theft — Technadu · August 14, 2026
  • Earth Simnavaz Cyberattacks — www.trendmicro.com · July 23, 2026
  • Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers — Linuxsecurity · June 17, 2026
  • UAT-8099 Targets IIS in Asia with BadIIS and GotoHTTP — Socprime · February 2, 2026
  • UAT-8099 Exploits IIS Servers Using Web Shell Attacks — Cyberpress · January 30, 2026
  • UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region — Cybersecuritynews · January 30, 2026
  • Cisco Talos uncovers UAT — Industrialcyber.Co · January 9, 2026

CVSS v3.1 Breakdown