Godzilla Webshell is a server-side webshell used for post-compromise remote control of web-accessible systems. It has been observed in intrusion activity where attackers first exploit vulnerable internet-facing applications and then deploy the webshell to execute commands, maintain access, and support follow-on operations. Reported use includes exploitation of Apache ActiveMQ vulnerability CVE-2023-46604 to execute Godzilla Webshell, as well as deployment during broader server intrusions in which operators tested multiple Chinese-language webshell frameworks after gaining code execution.
Godzilla is associated with hands-on-keyboard post-exploitation rather than initial compromise by itself. In observed incidents, operators uploaded or tested it after obtaining execution on target servers, alongside reverse shells, persistence tooling, scanners, brute-force frameworks, and lateral-movement utilities. This places it in the post-exploitation phase of attacks, where it can provide durable remote access and command execution on compromised hosts. It has appeared in campaigns affecting exposed server infrastructure, including Linux-based cloud environments and web application servers.
Available reporting supports classifying Godzilla as a webshell used for persistence and post-exploitation. Although it has been described as a Chinese webshell and has appeared in incidents involving Chinese-language tooling, its presence alone is not sufficient for reliable threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Red Canary detected an adversary executing discovery commands on dozens of cloud-based Linux endpoints vulnerable to a critical remote code vulnerability (CVE-2023-46604) in Apache ActiveMQ... Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware, along with Kinsing... Finally, the adversary used curl to download two ActiveMQ JAR files... These two JAR files constitute a legitimate patch for CVE-2023-46604. | ...adversaries are still exploiting the vulnerability to execute payloads such as Godzilla Webshell, and Ransomhub ransomware...
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
"On Nov. 22, Zoho released a security advisory alerting customers of active exploitation against newly registered CVE-2021-44077. The vulnerability impacted ServiceDesk Plus versions 11305 and below."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Godzilla is an open-source web shell used by attackers to maintain access to compromised systems. It is concealed within an unknown binary format to evade detection and is executed via ActiveMQ’s JSP engine.
Godzilla Webshell is a webshell payload used by attackers to maintain access and execute commands on compromised systems.
A webshell payload observed being executed through exploitation of Apache ActiveMQ CVE-2023-46604.
A Chinese webshell used by the attackers during post-exploitation testing to gain remote command execution and persistence on the compromised server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.