SLAYSTYLE is a Java-based web shell implemented as an Apache Tomcat Servlet Filter and deployed as a malicious WAR archive on compromised Tomcat servers. It has been observed in intrusions targeting Dell RecoverPoint for Virtual Machines appliances, where attackers abused CVE-2026-22769, a hard-coded credential vulnerability in the embedded Tomcat Manager, to authenticate, upload the WAR package, and gain root-level command execution on the underlying appliance. The malware has been attributed to activity tracked as UNC6201, a suspected PRC-nexus espionage cluster, and has been used alongside BRICKSTORM and GRIMBOLT during long-running post-compromise operations.
SLAYSTYLE functions as a server-side web shell that provides persistent remote access and supports post-exploitation activity on compromised systems. In observed campaigns it enabled command execution, facilitated persistence, and was used as an operational foothold for broader intrusion activity including lateral movement and covert access enablement. Investigators also recovered evidence of SLAYSTYLE being used on compromised VMware vCenter appliances to execute firewall manipulation commands that implemented Single Packet Authorization-style access controls, supporting stealthy command-and-control and operator access concealment.
Observed deployment has been tied to exploitation of enterprise edge and infrastructure appliances rather than commodity distribution. The malware specifically targets Apache Tomcat environments and has been documented on Linux-based Dell RecoverPoint for Virtual Machines appliances used in VMware environments. Its role in these intrusions is consistent with appliance-focused espionage tradecraft that favors durable access on systems that often lack traditional endpoint monitoring.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Most notably, CVE-2026-22769, a hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, was exploited as a zero day by the PRC linked threat cluster UNC6201 since mid 2024. Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability. | Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Google's threat intelligence team documented the actor delivering the BRICKSTORM backdoor, GRIMBOLT native backdoors, and the SLAYSTYLE webshell through this vulnerability.
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
An analysis of the compromised VMware vCenter appliances has also uncovered iptable commands executed by means of the web shell...
Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager, upload a malicious WAR file using the /manager/text/deploy endpoint, and then execute commands as root on the appliance.
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
Communicates with its C2 infrastructure over WebSockets, with some variants using DNS-over-HTTPS (DoH) to obscure C2 lookups from standard DNS monitoring
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Webshell delivered by UNC6201 via exploitation of Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769.
A Java Servlet Filter-based web shell for Apache Tomcat used for credential harvesting and passive backdoor access. Its implementation as a servlet filter makes it stealthier than typical uploaded web shells because defenders must inspect Tomcat application context or configuration rather than just the web root.
A web shell deployed on compromised Dell RecoverPoint for VMs appliances by UNC6201 after exploiting CVE-2026-22769.
Malware deployed post-exploitation in Dell RecoverPoint intrusions to support persistence and follow-on activity (exact functionality not detailed in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.