h4ntu shell is a PHP webshell used for post-compromise remote administration of web servers through a browser-accessible interface. It belongs to the long-running class of server-side webshells commonly deployed after attackers obtain the ability to upload or modify files on an internet-facing application. Detection coverage places it alongside other established PHP shell families such as c99, r57, b374k, and Weevely, indicating its role as an operator-controlled backdoor rather than a self-propagating threat.
As a webshell, h4ntu shell is designed to provide persistent remote access on compromised web infrastructure. Typical webshell functionality supported by the detection context includes command execution, file management, and broader post-exploitation activity on the hosting server. PHP webshells in this class commonly expose capabilities for browsing directories, uploading and modifying files, and executing system commands through PHP interpreter functions, enabling attackers to maintain access, stage additional tooling, and operate on the victim host after initial compromise.
The malware targets PHP-enabled web environments and runs on servers capable of executing PHP code. Because PHP web applications are commonly hosted on Linux and Windows web servers, h4ntu shell is relevant to both platforms where PHP is deployed. Its operational use is associated with unauthorized administration of compromised websites and servers rather than with a specific industry vertical, and it is best understood as a general-purpose web backdoor used in opportunistic or targeted intrusions against exposed web applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP webshell providing attacker-controlled remote access and command execution on web servers; referenced as a specific webshell family covered by new YARA detections.
Webshell detected via YARA rules using metadata and string patterns, including variants referencing 'powered by tsoi'.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.