MITRE ATT&CK Technique
T1505.003Web Shell
- First Reported
- Sep 26, 2026
- Latest Reported
- Sep 28, 2026
Official Description
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.(Citation: volexity_0day_sophos_FW)
In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)
In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. [China Chopper](https://attack.mitre.org/software/S0020) Web shell client).(Citation: Lee 2013)
- Tactics
- Persistence
- Platforms
- Linux, macOS, Network Devices, Windows
- Parent Technique
- T1505 · Server Software Component
- MITRE Version
- 1.5
- Last Modified
- May 12, 2026
Reported Context (3)
- A second-stage Java web shell injected itself into the server's Jetty servlet filter chain and accepted HTTP-header commands. PaperCut Zero-Days Used to Deploy AdaptixC2 and Compromise an Education Customer’s Domain
- The attacker installed a Godzilla-style web shell that handled HTTP requests in the ASP.NET server process without a separate .Aspx file. Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages
- UNC6240 placed JSP web shells in the PeopleSoft PSEMHUB.war directory for continued access and payload staging. ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273
CVE (4)
Malware (3)
Threat Actors (3)
MITRE ATT&CK (29)
Vendors (6)
Products (9)
Tools (14)
Industries (2)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.