Godzilla is a widely used web shell framework employed for persistent remote access on compromised web servers and application platforms. It is commonly observed after exploitation of internet-facing vulnerabilities in products such as Microsoft Exchange, IIS-hosted applications, VMware Workspace ONE Access and Identity Manager, Cisco SD-WAN Manager, and vulnerable CMS deployments including WordPress and Joomla. Operators use it as a post-exploitation foothold to execute commands, upload or drop additional payloads, and maintain access to compromised servers.
Godzilla is strongly associated with server-side web shell tradecraft rather than a single intrusion set. It has been used by multiple unrelated threat actors, including Chinese-speaking cybercrime operators conducting mass exploitation campaigns and China-aligned espionage clusters such as SHADOW-EARTH-053. It has also appeared in opportunistic exploitation of zero-day and N-day vulnerabilities, including ViewState deserialization attacks against ASP.NET applications and large-scale exploitation of exposed web applications and network management platforms.
The framework is notable for encrypted command-and-control communications and in-memory execution patterns. In Java deployments, Godzilla-style shells are known for dynamically loading Java bytecode directly into memory instead of storing full payload logic on disk, reducing forensic visibility. Observed variants have used XOR-encrypted traffic, and the framework supports remote command execution and staging of follow-on tooling such as Cobalt Strike, ShadowPad, miners, credential stealers, and other implants.
Godzilla is typically installed after successful exploitation rather than delivered directly through user-facing lures. Once deployed, it functions as a stealthy server-side backdoor that enables arbitrary command execution, payload delivery, and durable access for later operations including reconnaissance, credential theft, lateral movement, and broader post-compromise activity, depending on the actor’s objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla. The bug is a deserialization problem tracked as CVE-2026-5426 and can be abused without verification. It originates from the use of “shared hardcoded machine key in the web portal configuration.” | Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
We observed the vulnerability exploited to download webshells, including: ... The Godzilla Webshell that has also been used in previous campaigns exploiting other vulnerabilities.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
A torrent of proof-of-concept (PoC) exploits for React2Shell has hit the internet following the vulnerability's disclosure last week, and while security researchers say most are fake, ineffective and AI-generated slop, some have proven to be quite dangerous. CVE-2025-55182 was disclosed on Dec. 3 with a maximum CVSS score of 10, setting off urgent calls for immediate mitigation. The remote code execution (RCE) flaw stems from an unsafe deserialization issue in React Server Components (RSC) protocol that affects not only React open source software but other frameworks such as Next.js. The critical vulnerability came under exploitation shortly after public disclosure, with Amazon threat intelligence observing attacks from several China-nexus threat groups. Attacks against the vulnerability, which researchers refer to as "React2Shell," increased this week as opportunistic threat actors of all stripes launched campaigns with cryptominers, infostealers, backdoors, and more.
...active exploitation of a newly identified vulnerability (CVE-2021-40539) in ManageEngine ADSelfService Plus... rated critical... an authentication bypass vulnerability affecting ... REST API URLs that could enable remote code execution... reports of malicious cyber actors using exploits against CVE-2021-40539 to gain access... | (Updated November 19, 2021): APT actors are using the following suite of tools to enable this campaign: ... Godzilla – a Chinese language webshell.
"...this dropper deploys a Godzilla webshell which provides the actor with further access to and persistence in compromised systems."
The content states CVE-2023-46604 (Apache ActiveMQ) “was known to have been used in the Godzilla ransomware attack.”
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following successful exploitation, operators deployed GODZILLA web shells into Exchange and IIS directories to establish persistent remote access.
"...this dropper deploys a Godzilla webshell which provides the actor with further access to and persistence in compromised systems."
Web shells – AntSword, Behinder, China Chopper, Godzilla , giving the hackers backdoor access to the breached systems.
We observed the attackers deploying the GodZilla web shell, and a variation of AntSword
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Specifically, the warrants authorized the seizures of computer servers that launched and controlled the DDoS attacks, computer servers that relayed attack commands to a broader network of attack computers, and accounts containing the source code for the DDoS tools used by Anonymous Sudan.
Threat actors could modify a JavaScript file with code that asked users to run a ‘security authentication plugin’ and install a malicious script from a domain that hackers used.
WP-SHELLSTORM ... over 1.4 million targeted domains, 27 CVEs weaponized ... Most public reporting ... has focused entirely on the WordPress side. But the operator’s bash history reveals a second, parallel track: scanning and exploiting Apache Nacos, XXL-Job, and Spring Boot
Once running, it can browse and manage files, execute OS or PHP code, spin up reverse shells
Monitor for unusual child processes spawned by w3wp.exe . Commands observed include: ... powershell.exe
Monitor for unusual child processes spawned by w3wp.exe . Commands observed include: cmd.exe /c ... whoami
The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems, allowing the operators to run arbitrary bash commands.
A known indicator associated with the campaign includes the BLUEBEAM payload “LoadLibrary.dll” with SHA-256 hash 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2.
One particularly notable technique involved propagating malicious web shells across additional internal Exchange servers by copying ASPX files directly through administrative SMB shares.
Talos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device.
According to the indictment and a criminal complaint also unsealed today, since early 2023, the Anonymous Sudan actors and their customers have used the group’s Distributed Cloud Attack Tool (DCAT) to conduct destructive DDoS attacks and publicly claim credit for them. In approximately one year of operation, Anonymous Sudan’s DDoS tool was used to launch over 35,000 DDoS attacks.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell/tooling family mentioned only as part of tradecraft associated with Chinese-speaking forums.
A webshell framework used alongside the primary shell in the campaign, notable here for XOR-encrypted command-and-control traffic.
A webshell framework/tooling family referenced as part of the operator’s exploitation and shell-management workflow.
A webshell framework/tool that uses in-memory loading of Java bytecode for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.