Weevely is a stealth PHP web shell and post-exploitation framework used to maintain remote access to compromised web servers. It is typically deployed after attackers obtain the ability to write files to a web-accessible location through exploitation, credential abuse, or supply-chain compromise of internet-facing applications and supporting infrastructure. Once installed, it provides a command-line interface for remote administration of the compromised server and supports execution of system commands, file upload and download, and broader post-exploitation activity on the host. Weevely is designed to be compact and obfuscated, which has made it a longstanding target of web-shell detection signatures.
The malware is associated with intrusion activity against Linux-hosted PHP applications and web servers, and it has been observed as a pre-positioned access mechanism in broader operations involving lateral movement and persistence inside enterprise environments. Reporting has linked its use to compromises affecting critical infrastructure in Ukraine, where it was found alongside tunneling and backdoor tooling on vendor-connected systems used in industrial environments. More broadly, Weevely is widely used as an operator tool rather than being exclusive to a single threat actor, and it commonly appears in web intrusion and post-exploitation workflows wherever PHP execution is available on the target server.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...в каталогах з СПЗ було виявлено заздалегідь створений PHP-вебшелл WEEVELY...
...в каталогах з СПЗ було виявлено заздалегідь створений PHP-вебшелл WEEVELY...
...в каталогах з СПЗ було виявлено заздалегідь створений PHP-вебшелл WEEVELY...
6 distinct techniques documented for this family, organized by ATT&CK tactic.
rule webshell_simple_backdoor { ... $s4 = "system($cmd);" ... }
The purpose of disable_functions is to enhance the security of PHP applications by preventing the execution of potentially dangerous functions that could be abused by attackers to execute malicious code... examples include exec(), system(), shell_exec(), popen(), and proc_open().
Descriptions repeatedly identify server-side implants such as "Web shell - file ASPXspy2.aspx", "Detects a ASPX web shell", "Detects JexBoss JSPs", and "Webshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of it". | The content is a large YARA ruleset explicitly focused on web shells, e.g. rule names and descriptions such as "Webshell_Insomnia", "JSP_Browser_APT_webshell", "WEBSHELL_ASPX_Mar21_1", and "Detects a tiny webshell - chine chopper".
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP webshell framework used to provide remote command execution and post-exploitation capabilities on compromised web servers; detected via YARA based on code/content patterns.
A stealth PHP web shell used to maintain remote access and execute commands on compromised web servers.
A PHP webshell/backdoor framework that generates obfuscated PHP payloads and enables remote control of compromised servers, including command execution, file transfer, database manipulation, and backdoor access.
PHP webshell used for remote command execution and persistence on web servers; found pre-positioned in software directories on targeted systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.