Mushr00w is a financially motivated cybercriminal identity associated with a small Telegram-based marketplace for the sale of webshell access, exploits, and related services. The identity has been linked to defacements of Malaysian and Ukrainian government websites and to advertising access to compromised educational and government-themed websites. Mushr00w participated in ZeroDay Commerce and connected communities, where sellers offered webshells with terminal and file-management functionality, purported administrator access, escrow, refunds, and limited guarantees. The actor has also sought WordPress exploitation resources and has been associated by branding with PHP webshell activity exploiting critical vulnerabilities in public-facing web applications, although branding alone does not conclusively establish responsibility for every observed exploitation campaign. Associated marketplace participants include accounts known as VX-encoded and another seller involved in a public dispute with Mushr00w over alleged theft of shell access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with active exploitation of the Super Forms WordPress plugin arbitrary-file-upload flaw to upload the Mushr00w_upl.php web-shell dropper. The web shell can deploy additional malware, phishing kits, or spam files; reported follow-on capabilities include arbitrary command execution, local administrator-account creation, file and directory discovery, and data exfiltration.
Associated with branding on a PHP uploader webshell and reportedly with a recent website-defacement incident targeting Malaysia's Health Ministry via exploitation of a Joomla extension vulnerability. Attribution to the Super Forms exploitation activity is explicitly uncertain.
Active participant in a Telegram-based webshell marketplace, linked to website defacements and repeated advertisements for selling webshell access, including access to government and education domains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.