Behinder, also known as Ice Scorpion, Rebeyond, and 冰蝎, is a publicly available cross-platform web shell framework widely used as a post-exploitation backdoor on compromised web servers and application platforms. It supports multiple server-side technologies including PHP, JSP/Java, ASP, ASPX, and C#, and is operated through a Java-based client. Behinder is commonly deployed after exploitation of internet-facing applications and appliances to maintain covert remote access, execute commands, manage files, and stage follow-on intrusion activity.
A defining characteristic of Behinder is its encrypted command channel and in-memory execution model. Java variants can dynamically load attacker-supplied bytecode directly into memory through reflection and class-loading mechanisms, while memory-resident implementations such as MemShell-style deployments can persist inside application processes without relying on a conventional on-disk web shell. Observed samples have used layered obfuscation, including Unicode encoding, Base64 wrapping, and Zelix KlassMaster obfuscation, to evade static detection and web application firewalls. ASP.NET-related activity has also shown Behinder-associated in-memory modules and plugin loading behavior.
Behinder provides operators with remote command execution, file management, and extensibility through additional payloads or modules. Reported functionality includes upload and download operations, deletion, virtual terminal access, custom persistence options, and support for in-memory shell injection. It has also been associated with proxying and broader post-exploitation workflows through integration or coexistence with other offensive tooling. In incident reporting, Behinder has been used to backdoor systems, facilitate credential access, support lateral movement, and enable access to victim emails and files.
The framework is frequently observed in exploitation of enterprise edge devices and web applications. It has been reported in intrusions involving SonicWall products, Ivanti Cloud Service Appliance, Ivanti Endpoint Manager Mobile, Trimble Cityworks, Microsoft Exchange-adjacent environments, and other compromised IIS, Tomcat, PHP, and Java application servers. Multiple threat actors have deployed Behinder, including clusters assessed as Chinese-speaking or China-nexus, as well as actors involved in ransomware and mass exploitation campaigns. Its broad availability, multi-language support, encrypted traffic, and mature operator ecosystem have made it one of the most recognizable and commonly encountered web shell families in modern intrusion response.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-20022 (CVSS: 6.7): Post-authentication arbitrary file upload vulnerability. A previously authenticated threat actor may exploit this vulnerability in order to upload arbitrary files to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
On June 2nd, 2022, Atlassian disclosed a critical vulnerability impacting the Confluence collaboration tool, tracked as CVE-2022-26134; active exploitation of the vulnerability has been confirmed. CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. | Attacks observed by Volexity resulted in the deployment of the open-source webshell BEHINDER, a file upload webshell, and the China Chopper webshell.
CVE-2021-20021 (CVSS: 9.4): Unauthorized administrative account creation vulnerability. Exploitation allows a remote and unauthenticated attacker to create an administrative account by sending a crafted HTTP request to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
CVE-2021-20023 (CVSS: 6.7): Post-authentication arbitrary file read vulnerability. A previously authenticated threat actor may exploit this vulnerability in order to read arbitrary files to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Mandiant and Palo Alto’s Unit42 have also reported on Behinder and Godzilla web shells deployed upon initial access in high-profile intrusions such as SonicWall, and ProxyShell. | Also referred to as Ice Scorpion, Behinder is publicly available and maintained by GitHub user rebeyond.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код... Unit 42 фиксирует: до момента публикации 29 января 2026 уже шла активная эксплуатация. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
Cisco Talos has observed exploitation of CVE-2025-0994, a remote-code-execution vulnerability in Cityworks, a popular asset management system. The Cybersecurity and Infrastructure Security Agency (CISA) and Trimble have both released advisories pertaining to this vulnerability... | These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg or generated via the Behinder (“Ice Scorpion”) webshell framework were found.
These three zero-days were also actively exploited by a group Mandiant tracks as UNC2682 to backdoor systems using BEHINDER web shells, allowing them to move laterally through victims' networks and access emails and files.
These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
Web shells – AntSword, Behinder, China Chopper, Godzilla , giving the hackers backdoor access to the breached systems.
"...includes webshells such as Behinder, Godzilla, and Neo-reGeorg..."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The China Chopper web shell has long been utilized post exploit to blend in network traffic, providing the attacker full command prompt access to move around the network.
The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems, allowing the operators to run arbitrary bash commands.
The sample references Java classes such as Thread.currentThread().getContextClassLoader() and ClassLoader.
CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. Exploitation of this vulnerability would allow an unauthenticated and remote actor to execute code on vulnerable devices
<%\u0074\u0072\uuu0079 {\uuu000a\uuu0020 \uuu0020 C\u006cas\u0073\uuu004co\u0061d\uu0065\uu0072 ... | 整个内存马过Waf的处理流程如下 冰蝎内存马-->ZKM15混淆-->class文件输出为Base64文件-->ZKM15混淆-->class文件输出为Base64文件-->特殊Unicode编码 | The sample is heavily encoded/obfuscated with escaped Unicode sequences and a large embedded Base64-like blob.
final Cipher instance = Cipher . getInstance ( "AES" ); instance . init ( 2 , new SecretKeySpec ((( String ) httpServletRequest . getSession (). getAttribute ( "u" )). getBytes (), "AES" ));
What caught my eye was the in-memory web shell referred to as MemShell... The try block in Figure 7 implements MemShell
This type of webshell is widely used... by dynamically loading Java bytecode directly into memory instead of storing it on disk.
java . lang . reflect . Method defineClzMethod = clzLoader . loadClass ( "java.lang.ClassLoader" ). getDeclaredMethod ( "defineClass" , String . class , byte []. class , int . class , int . class ); defineClzMethod . setAccessible ( true ); Class clz = ( Class ) defineClzMethod . invoke ( clzLoader , clzName , bytecode , 0 , bytecode . length ); clz . newInstance ();
Talos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device.
if ( httpServletRequest . getHeader ( "User-Agent" ) != null && httpServletRequest . getHeader ( "User-Agent" ). equals ( "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/531.26 (KHTML, like Gecko) Chrome/86.0.4240.138 Safari/531.26" ))
Figure 11: Packet capture of POST requests over port 80 Figure 12: Behinder HTTP POST request with encoded data in HTTP body
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source web shell mentioned as a comparison point for lightweight shells commonly reused by attackers.
Referenced as the model/comparison point for ORANGETAIL; not the malware primarily deployed in this incident.
A known webshell mentioned only as a comparison point for ORANGETAIL’s functionality and design.
A web shell framework referenced as the model for ORANGETAIL; mentioned for comparison rather than as the primary malware deployed in this incident.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.