P.A.S. Webshell, also known as Fobushell, is a PHP web shell used to obtain remote access and command execution on compromised web servers. It has been observed on internet-exposed Linux-hosted web applications, including Centreon servers, and is associated in public reporting with Sandworm-linked intrusions as well as broader use by other threat actors that rely on public offensive tooling. The malware is designed for post-exploitation control of a web server and supports a range of operator actions including file copying, reverse shell creation through Perl scripts, network and port scanning, inspection of PHP server configuration, reading local account information such as the system password file on Unix-like hosts, deletion of scripts after execution, and password-gated access using a decryption mechanism. These features make it suitable for persistence, reconnaissance, lateral discovery, and follow-on command execution from a compromised web application context. P.A.S. Webshell has been identified as a backdoor deployed on exposed Centreon systems during a multi-year intrusion campaign affecting French entities, particularly IT and web-hosting providers, where it was used alongside the Exaramel implant. It is also referenced as tooling used by APT28 and by Sandworm-related operations, reflecting its role as a reusable, publicly available web shell rather than an actor-exclusive capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
Fox Kitten has used a Perl reverse shell to communicate with C2. P.A.S. Webshell has the ability to create reverse shells with Perl scripts. SpeakUp uses Perl scripts. Windigo has used a Perl script for information gathering. | Bonadan can create bind and reverse shells on the infected system. Kessel can create a reverse shell... WINERACK can create a reverse shell... P.A.S. Webshell has the ability to create reverse shells with Perl scripts.
"Execution T1059.004 Command and Scripting Interpreter - Unix Shell Linux shell use" and "OS.ShellExecute – runs a shell command"
During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. Fox Kitten has used a Perl reverse shell to communicate with C2. P.A.S. Webshell has the ability to create reverse shells with Perl scripts. Windigo has used a Perl script for information gathering.
ANSSI has been informed of an intrusion campaign targeting the monitoring software Centreon distributed by the French company CENTREON which resulted in the breach of several French entities.
Descriptions repeatedly identify server-side implants such as "Web shell - file ASPXspy2.aspx", "Detects a ASPX web shell", "Detects JexBoss JSPs", and "Webshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of it". | The content is a large YARA ruleset explicitly focused on web shells, e.g. rule names and descriptions such as "Webshell_Insomnia", "JSP_Browser_APT_webshell", "WEBSHELL_ASPX_Mar21_1", and "Detects a tiny webshell - chine chopper".
Examples include "eval(gzinflate(str_rot13(base64_decode('", "Obfuscation provided by FOPO", and encoded constructs such as "preg_replace(\"/.*/e\",\"\\x65\\x76\\x61\\x6C...".
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Webshell that uses a decryption mechanism to process a supplied password and enable execution.
Web shell that can copy files on compromised hosts.
Web shell malware that deletes scripts after execution.
Webshell deployed on compromised Centreon systems (2017–2020 timeframe) to enable attacker access; used alongside Exaramel implants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.