SLAYSTYLE is a Java-based web shell used as a persistent backdoor on Apache Tomcat servers, particularly in compromises of Dell RecoverPoint for Virtual Machines appliances. It has been described as a JSP web shell and as a Java Servlet Filter-based implant packaged in a malicious WAR archive and deployed through Tomcat Manager. In observed intrusions, successful deployment gave attackers root-level command execution on the compromised appliance and enabled follow-on post-exploitation activity.
SLAYSTYLE has been associated with the suspected PRC-nexus threat cluster UNC6201 in long-running espionage intrusions exploiting CVE-2026-22769, a hard-coded credential vulnerability in Dell RecoverPoint for Virtual Machines. The actor used Tomcat Manager access to upload the malicious WAR containing SLAYSTYLE, then leveraged the foothold for persistence, lateral movement, and deployment of additional malware including BRICKSTORM and GRIMBOLT. Investigators also observed SLAYSTYLE being used in post-compromise tradecraft on VMware-related infrastructure, including execution of iptables-based Single Packet Authorization logic on compromised vCenter appliances to conceal access paths.
The malware targets Linux-based appliance environments running Apache Tomcat, especially edge and virtualization-management systems that often lack traditional endpoint monitoring. Its role in these intrusions is best characterized as a server-side web shell and backdoor that provides durable remote command execution and supports broader post-exploitation operations by advanced threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On February 17th, 2026, Dell disclosed a maximum severity zero-day vulnerability in Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769 (CVSS: 10), is due to hard coded credentials. A threat actor with knowledge of the credentials could exploit the vulnerability to enable remote access and root-level persistence. CVE-2026-22769 is reported to have been under active exploitation since at least mid-2024. | Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: SLAYSTYLE (aka BEEFLUSH): a JavaServer Pages (JSP) webshell that functions as a backdoor
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following initial access and exploitation of CVE-2026-22769, UNC6201 was observed deploying three different backdoors to enable persistent access: SLAYSTYLE (aka BEEFLUSH): a JavaServer Pages (JSP) webshell that functions as a backdoor
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
SLAYSTYLE is a web shell targeting Apache Tomcat servers, implemented as a Java Servlet Filter.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
An analysis of the compromised VMware vCenter appliances has also uncovered iptable commands executed by means of the web shell...
Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager, upload a malicious WAR file using the /manager/text/deploy endpoint, and then execute commands as root on the appliance.
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager
Communicates with its C2 infrastructure over WebSockets, with some variants using DNS-over-HTTPS (DoH) to obscure C2 lookups from standard DNS monitoring
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Webshell delivered by UNC6201 via exploitation of Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769.
A Java Servlet Filter-based web shell for Apache Tomcat used for credential harvesting and passive backdoor access. Its implementation as a servlet filter makes it stealthier than typical uploaded web shells because defenders must inspect Tomcat application context or configuration rather than just the web root.
A web shell deployed on compromised Dell RecoverPoint for VMs appliances by UNC6201 after exploiting CVE-2026-22769.
Malware deployed post-exploitation in Dell RecoverPoint intrusions to support persistence and follow-on activity (exact functionality not detailed in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.