Web Shell - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
November 1, 2025
Last Seen
June 17, 2026

Web Shell is a mitre_attack tracked across 13 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 1, 2025; most recent activity June 17, 2026.

Related Threat Clusters

  • UAT-7290 Cyber Espionage Targets South Asian Telecoms

    UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…

    2 articles · Updated January 12, 2026
  • Critical Joomla JCE Vulnerability Under Active Exploitation

    A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…

    33 articles · Updated June 17, 2026
  • Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities

    An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…

    8 articles · Updated November 12, 2025
  • APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems

    An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…

    16 articles · Updated November 18, 2025
  • China's Brickstorm Malware Compromises US Critical Networks

    Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…

    10 articles · Updated December 4, 2025
  • Microsoft's .NET RCE Bug Remains Unfixed, Affecting Enterprise Applications

    Security researchers have identified a remote code execution (RCE) vulnerability in the .NET framework that impacts various enterprise applications. Piotr Bazydło from watchTowr presented these findings at Black Hat…

    3 articles · Updated December 10, 2025
  • CISA Flags OpenPLC ScadaBR Vulnerability as Actively Exploited

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the OpenPLC ScadaBR vulnerability, tracked as CVE-2021-26829, to its Known Exploited Vulnerabilities catalog after confirming active…

    2 articles · Updated December 2, 2025
  • CISA Alerts on Chinese BrickStorm Malware Targeting VMware Servers

    CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and…

    3 articles · Updated December 4, 2025
  • Cisco IOS XE Vulnerability Exploited to Deploy BADCANDY Web Shell

    Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This attack targets devices running the affected software, allowing unauthorized access and control. The ongoing…

    3 articles · Updated November 1, 2025
  • Cisco IOS XE Vulnerability Exploited for BADCANDY Web Shell Deployment

    Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This exploitation is occurring in the wild, affecting systems running the vulnerable software. The BADCANDY web shell…

    3 articles · Updated November 1, 2025

Recent Intelligence Reports

  • Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers — Linuxsecurity · June 17, 2026
  • UAT-8099 Targets IIS in Asia with BadIIS and GotoHTTP — Socprime · February 2, 2026
  • UAT-8099 Exploits IIS Servers Using Web Shell Attacks — Cyberpress · January 30, 2026
  • UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region — Cybersecuritynews · January 30, 2026
  • Cisco Talos uncovers UAT — Industrialcyber.Co · January 9, 2026
  • Microsoft won’t fix .NET RCE bug affecting slew of enterprise apps, researchers say — Theregister · December 10, 2025
  • Chinese cyberspies target VMware vSphere for long — Csoonline · December 5, 2025
  • Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware — Cyberscoop · December 4, 2025

CVSS v3.1 Breakdown