JSP webshell is a server-side webshell used in active exploitation of SAP NetWeaver systems, particularly via the unrestricted file upload vulnerability CVE-2025-31324 in SAP NetWeaver Visual Composer. In the reported attacks, adversaries uploaded malicious JSP files through the /developmentserver/metadatauploader endpoint into the j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root/ directory to obtain persistent backdoor access. Observed filenames included helper.jsp, cache.jsp, rrx.jsp, and dyceorp.jsp. The webshells enabled unauthorized file upload and arbitrary command execution on compromised servers, and some were noted to use code from public GitHub repositories. Post-exploitation activity associated with these intrusions included use of Brute Ratel for command-and-control and in-memory execution, and Heaven’s Gate for evasion. The exploitation has been attributed to multiple threat actors, including BianLian and RansomEXX (Storm-2460), with reporting also noting interest from Chinese- and Russian-linked actors and possible involvement of initial access brokers. Targeted environments were high-value SAP NetWeaver deployments used by government agencies and large enterprises. Related attack chains also combined CVE-2025-31324 with CVE-2025-42999 for stealthier in-memory execution. High-confidence indicators mentioned in the content include the upload path j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root/, the vulnerable endpoint /developmentserver/metadatauploader, webshell filenames helper.jsp, cache.jsp, rrx.jsp, and dyceorp.jsp, and associated infrastructure such as dns.telemetrymasterhostname.com, 184.174.96.74, 184.174.96.70, and aaaaabbbbbbb.eastus.cloudapp.azure.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Haavoittuvuus vaikuttaa SAP NetWeaver Visual Composer Frameworkin 7.xx-versioihin ja service packeihin. Haavoittuvuus mahdollistaa mielivaltaisen koodin suorittamisen SAP-sovellusta pyörittävällä palvelimella ja palvelimen haltuunoton... Kyberturvallisuuskeskuksella on tiedossa haavoittuvuuden hyväksikäyttöä Suomessa... Haavoittuvuus on nollapäivähaavoittuvuus... Haavoittuvuus mahdollistaa tiedostojen lähettämisen ja suorittamisen palvelimella ilman käyttäjän autentikointia... Havaintojemme perusteella haavoittuvuuden avulla järjestelmiin on asennettu ns. webshellejä... Uutisia löytää esimerkiksi NVD:n CVE-2025-31324 -artikkelista.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious JSP webshells are uploaded to SAP NetWeaver Visual Composer servers via the CVE-2025-31324 vulnerability, providing attackers with persistent remote access and control over the compromised system.
Malicious JSP webshells are uploaded to SAP NetWeaver directories via exploitation of vulnerabilities, allowing attackers to execute arbitrary commands, upload files, and maintain persistent access to compromised systems. These webshells are lightweight, compatible, and enable remote control and post-exploitation activities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.