BLUEBEAM, also known as Godzilla, is a .NET-based in-memory web shell used to maintain access to compromised Microsoft IIS and ASP.NET servers. It runs within the IIS worker process and receives encrypted data in HTTP POST requests to execute commands and payloads, reducing disk-based forensic artifacts. It has been deployed following exploitation of exposed web applications, including forged ASP.NET ViewState deserialization payloads affecting KnowledgeDeliver LMS deployments. In that activity, operators modified web-server permissions and legitimate JavaScript resources, using a fake authentication-plugin prompt to facilitate subsequent Cobalt Strike Beacon infections on user workstations. APT41’s DUST activity has also used BLUEBEAM alongside ANTSWORD for persistence on compromised servers, including exposed Apache Tomcat Manager systems. BLUEBEAM is associated with post-compromise command execution, persistence, and in-memory defense evasion on Windows web servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A newly disclosed zero-day vulnerability in the KnowledgeDeliver Learning Management System (LMS) has been actively exploited in the wild to deploy the BLUEBEAM in-memory web shell, according to Mandiant’s incident response findings. The flaw, now tracked as CVE-2026-5426, enables unauthenticated remote code execution (RCE) and affects deployments that relied on default ASP.NET configuration settings prior to February 24, 2026. | Following initial access, the attacker deployed BLUEBEAM, a .NET-based web shell also known as Godzilla. Unlike traditional web shells that rely on files stored on disk, BLUEBEAM operates entirely in memory within the IIS worker process (w3wp.exe), significantly reducing its forensic footprint.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent campaigns, ANTSWORD and BLUEBEAM web shells were seen on exposed Tomcat Apache Manager server to execute certutil.exe and download the DUSTPAN dropper.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory .NET web shell deployed after exploitation of the KnowledgeDeliver LMS zero-day. It runs inside the IIS worker process, communicates via encrypted HTTP POST requests, and enables command execution, payload upload, and persistence while minimizing file-based forensic artifacts.
BLUEBEAM is a web shell used by APT41 for remote access and command execution on compromised servers as part of their cyberespionage toolkit.
Web shell used for persistence on compromised servers.
Web shell used for persistence/remote management of compromised servers in APT41 (DUST) operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.