LocalOlive is an ASPX web shell that Microsoft has identified as exclusive to a Seashell Blizzard (Sandworm) initial-access subgroup linked to Russia’s GRU Unit 74455. It has reportedly been in use since at least late 2021 and has been described as a signature Sandworm-associated web shell. Its documented capabilities include command-and-control, command execution, file transfer or file upload, opening a TCP port, and facilitating delivery of next-stage payloads such as Chisel, plink, and rsockstun. Multiple sources in the content state it has been used to provide initial access on compromised perimeter infrastructure after exploitation of unpatched or publicly exposed internet-facing systems. Reported victim sectors and geographies tied to the broader subgroup activity include energy, oil and gas, telecommunications, shipping, arms manufacturing, government, and organizations in Ukraine, Europe, Central Asia, South Asia, the Middle East, and later the United States, United Kingdom, Canada, and Australia. In separate 2025 intrusions against Ukrainian organizations, investigators observed LocalOlive deployed on public-facing servers as part of Russian-linked activity focused on persistence and credential theft, although those investigators said they could not independently confirm Sandworm attribution. High-confidence network indicators mentioned in the content for related activity include hwupdates[.]com, cloud-sync[.]org, 103.201.129[.]130, 185.145.245[.]209, and ciscoheartbeat[.]com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To date, at least eight vulnerabilities... have been exploited by this subgroup: Zimbra Collaboration (CVE-2022-41352)... On October 24, 2022, the initial access subgroup successfully exploited CVE-2022-41352. This Zimbra Collaborative vulnerability allows a threat actor to deploy web shells and other arbitrary files by sending an email with a specially crafted attachment... | Detected as LocalOlive, this web shell is identified on compromised perimeter infrastructure and serves as the subgroup’s primary means of achieving C2 and deploying additional utilities to compromised infrastructure.
To date, at least eight vulnerabilities... have been exploited by this subgroup: Microsoft Exchange (CVE-2021-34473)... We have observed web shells deployed following exploitation of vulnerabilities in Microsoft Exchange (CVE-2021-34473)... | Detected as LocalOlive, this web shell is identified on compromised perimeter infrastructure and serves as the subgroup’s primary means of achieving C2 and deploying additional utilities to compromised infrastructure.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the webshells used was Localolive, which, according to Microsoft, is associated with a sub-group of the Russian Sandworm group (aka Seashell Blizzard) and has previously been used to provide initial access in a Sandworm campaign.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers gained access to the business services organization by deploying webshells on public-facing servers, most likely by exploiting one or more unpatched vulnerabilities. One of the webshells used was Localolive, which, according to Microsoft, is associated with a sub-group of the Russian Sandworm group (aka Seashell Blizzard).
After deploying web shells, the initial access subgroup then executes specific sequential commands below likely used to fingerprint and attribute victim networks...
Following exploitation, the subgroup used two methods of payload retrieval to install RMM agents on affected servers: Retrieval of Atera Agent installers from legitimate agent endpoints... via Bitsadmin and curl... [and] from actor-controlled virtual private server (VPS) infrastructure.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Webshell used on public-facing servers to provide initial access and remote control; associated (per Microsoft) with a Sandworm/Seashell Blizzard sub-group.
Webshell used for persistent remote access and command execution on compromised public-facing servers, enabling follow-on activity using built-in/admin tools (“living off the land”).
A custom webshell linked in the reporting to Sandworm activity and used to provide initial access on public-facing servers.
Web shell used to facilitate delivery of next-stage payloads and maintain persistent access to compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.