Godzilla Webshell is a webshell payload observed by Red Canary being deployed by adversaries exploiting Apache ActiveMQ vulnerability CVE-2023-46604 on cloud-based Linux servers. In the cited reporting, it is mentioned as one of several payloads delivered via continued exploitation of this nearly three-year-old flaw, alongside Ransomhub ransomware. The provided content does not describe Godzilla Webshell’s internal functionality, infection mechanism beyond post-exploitation deployment through CVE-2023-46604, specific persistence methods, or concrete indicators of compromise. High-confidence context from the reporting is that attackers continue to use the ActiveMQ vulnerability as an access vector to execute payloads including Godzilla Webshell, indicating relevance to exposed ActiveMQ environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Red Canary detected an adversary executing discovery commands on dozens of cloud-based Linux endpoints vulnerable to a critical remote code vulnerability (CVE-2023-46604) in Apache ActiveMQ... Security researchers have previously identified adversaries exploiting CVE-2023-46604 for malware deployment, to spread TellYouThePass, Ransomhub and HelloKitty ransomware, along with Kinsing... Finally, the adversary used curl to download two ActiveMQ JAR files... These two JAR files constitute a legitimate patch for CVE-2023-46604. | ...adversaries are still exploiting the vulnerability to execute payloads such as Godzilla Webshell, and Ransomhub ransomware...
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
"On Nov. 22, Zoho released a security advisory alerting customers of active exploitation against newly registered CVE-2021-44077. The vulnerability impacted ServiceDesk Plus versions 11305 and below."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
We observed the vulnerability exploited to download webshells, including: A basic implementation that read a GET parameter value, Base64 decoded it, and used a ClassLoader to load the result. The Godzilla Webshell that has also been used in previous campaigns exploiting other vulnerabilities.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Godzilla is an open-source web shell used by attackers to maintain access to compromised systems. It is concealed within an unknown binary format to evade detection and is executed via ActiveMQ’s JSP engine.
Godzilla Webshell is a webshell payload used by attackers to maintain access and execute commands on compromised systems.
A webshell payload observed being executed through exploitation of Apache ActiveMQ CVE-2023-46604.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.