Tiny is a PHP web shell/backdoor. The provided content describes it as using PHP to create a backdoor that gives a threat actor remote access to a compromised system and can also tunnel or route traffic. It is publicly known as the Tiny web shell and is referenced alongside ChunkyTuna and China Chopper.
The content associates Tiny with an Iran-based threat actor correlated with Pioneer Kitten / UNC757 that targeted U.S. federal agencies and U.S.-based organizations in sectors including information technology, government, healthcare, financial services, insurance, media, and related industries. In the described campaigns, the actor gained initial access by exploiting known vulnerabilities in internet-facing infrastructure, particularly Pulse Secure VPN, Citrix NetScaler, and F5 BIG-IP devices, including CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, and CVE-2020-5902. After exploitation, the actor installed web shells including Tiny to maintain persistence for extended periods.
The malware analysis content further states that Tiny variants execute Base64-decoded POST data via PHP eval using a parameter of the form "citrix@[Redacted]." Specific Tiny-related indicators mentioned are tiny_webshell (SHA256: b36288233531f7ac2e472a689ff99cb0f2ac8cba1b6ea975a9a80c1aa7f6a02a) and a 57-byte file named content (SHA256: 4a1fc30ffeee48f213e256fa7bff77d8abd8acd81e3b2eb3b9c40bd3e2b04756). The broader advisory also notes file paths on NetScaler systems that may indicate Tiny deployment following exploitation of CVE-2019-19781, including /netscaler/ns_gui/admin_ui/rdx/core/css/images/css.php. Overall, Tiny is characterized in the source material as a lightweight PHP backdoor used for persistent remote access and traffic tunneling in post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781. | Tool Tiny web shell Detail Tiny uses Hypertext Preprocessor (PHP) to create a backdoor. It has the capability to allow a threat actor remote access to the system and can also tunnel or route traffic.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tool Tiny web shell Detail Tiny uses Hypertext Preprocessor (PHP) to create a backdoor. It has the capability to allow a threat actor remote access to the system and can also tunnel or route traffic.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.