Behinder, also known as Ice Scorpion, Rebeyond, and 冰蝎, is a widely used cross-platform web shell framework associated with post-compromise persistence and remote control of web servers. It supports major server-side environments including PHP, Java, and ASP.NET, and is commonly deployed after exploitation of internet-facing applications and appliances. Behinder is especially notable for encrypted operator-to-implant communications and for designs that dynamically load code into memory, reducing on-disk artifacts and complicating forensic detection.
In Java and .NET deployments, Behinder-style implementations commonly act as in-memory loaders for additional modules and post-exploitation functionality. Reported capabilities include remote command execution, file management, proxying or tunneling, and modular extension through plugins. Variants and related tooling have been observed using encrypted channels, including AES-protected communications, while some modified samples replace standard encryption with simpler encoding schemes. Behinder has also been linked to memory-resident modules and reflective or dynamic loading approaches that help evade file-based defenses.
Behinder is frequently observed in intrusion sets targeting enterprise web infrastructure, including application servers, collaboration platforms, VPN appliances, mobile device management systems, and network management products. It has been deployed following exploitation of products such as Atlassian Confluence, Ivanti EPMM, SonicWall SMA, Cisco SD-WAN, Trimble Cityworks, and SharePoint/IIS environments. Multiple investigations have associated its use with China-nexus intrusion activity and with both espionage-oriented and opportunistic post-exploitation operations, although the tool itself is broadly available and not exclusive to a single actor.
Because Behinder provides durable remote access to compromised web applications and servers, it is commonly used as a stealthy backdoor for persistence, command execution, credential-access follow-on activity, lateral movement support through proxying, and broader post-exploitation operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код... Unit 42 фиксирует: до момента публикации 29 января 2026 уже шла активная эксплуатация. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
Cisco Talos has observed exploitation of CVE-2025-0994, a remote-code-execution vulnerability in Cityworks, a popular asset management system. The Cybersecurity and Infrastructure Security Agency (CISA) and Trimble have both released advisories pertaining to this vulnerability... | These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
Following their exploitation, the threat actor deployed a variant of the Behinder webshell under the filename “conf.jsp”.
Following their exploitation, the threat actor deployed a variant of the Behinder webshell under the filename “conf.jsp”.
Following their exploitation, the threat actor deployed a variant of the Behinder webshell under the filename “conf.jsp”.
In the breach analyzed by Volexity, threat actors installed BEHINDER, a JSP web shell that allows threat actors to execute commands on the compromised server remotely.
Mandiant disclosed the vulnerability CVE-2021-20023 to SonicWall PSIRT on April 6, 2021... a patch became available April 19. To mitigate the three CVEs, Mandiant and SonicWall recommend upgrading Email Security to version 10.0.9.6173 (Windows) or 10.0.9.6177 (Hardware & ESXi Virtual Appliances).
Mandiant disclosed the vulnerabilities CVE-2021-20021 and CVE-2021-20022 to SonicWall PSIRT on March 26, 2021... a hotfix became available on April 9, 2021... To mitigate the three CVEs, Mandiant and SonicWall recommend upgrading Email Security to version 10.0.9.6173 (Windows) or 10.0.9.6177 (Hardware & ESXi Virtual Appliances).
SonicWall has deployed Intrusion Prevention System (IPS) signatures... IPS Signature : 15520 WEB-ATTACKS SonicWall Email Security (CVE-2021-20022 Vulnerability) ... Mandiant disclosed the vulnerabilities CVE-2021-20021 and CVE-2021-20022... a hotfix became available on April 9, 2021.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
Use of Chinese-documented tooling (e.g., Behinder, VShell), and operational activity aligned with China Standard Time (UTC+8).
Web shells – AntSword, Behinder, China Chopper, Godzilla , giving the hackers backdoor access to the breached systems.
"...includes webshells such as Behinder, Godzilla, and Neo-reGeorg..."
FireEye Malware File Scanning ... FE_Webshell_JSP_BEHINDER_1 ... Webshell.JSP.BEHINDER ... Webshell.JSP.BEHINDER.MVX
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell framework referenced as the model for ORANGETAIL; mentioned for comparison rather than as the primary malware deployed in this incident.
Referenced as the model for ORANGETAIL's webshell design.
A webshell framework/tool noted for dynamically loading Java bytecode directly into memory rather than writing payloads to disk.
Java web shell with encrypted communications used for persistence and remote control after Ivanti EPMM compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.