ASPXSpy is an ASP.NET web shell used to provide persistent backdoor access on compromised Microsoft IIS servers. It is publicly available and has appeared both as an off-the-shelf tool and in modified variants such as ASPXTool. Operators use it after server compromise to execute commands through the web server, maintain access, and support follow-on intrusion activity.
ASPXSpy has been associated with multiple state-linked and espionage-oriented intrusion sets, including HAFNIUM, APT27/BRONZE UNION/Threat Group 3390, APT39, Lebanese Cedar, Agrius, Gelsemium-linked activity, and XE Group exploitation of VeraCore. It has been deployed in compromises involving Microsoft Exchange ProxyLogon exploitation, SharePoint and other internet-facing application compromise, and exploitation of public-facing web servers through n-day vulnerabilities or SQL injection. In several campaigns it served as the initial persistent foothold after exploitation, enabling subsequent command execution, reconnaissance, credential theft, lateral movement, and data exfiltration by the operators.
The malware targets Windows-based web infrastructure running ASP.NET under IIS. Its role is primarily post-exploitation persistence and remote administration of the compromised server rather than autonomous propagation. Variants have been observed modified or obfuscated, including base64-encoded forms used for defense evasion. ASPXSpy is widely recognized as part of the broader ecosystem of ASPX web shells commonly used in long-term espionage intrusions against government, telecommunications, defense, education, healthcare, legal, and other strategically relevant sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
CVE-2024-57968 (CVSS skóre 9,9) Kritická zero-day zraniteľnosť Advantive VeraCore umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
CVE-2025-25181 (CVSS skóre 5,8) Zero-day zraniteľnosť v komponente timeoutWarning.asp umožňuje vzdialeným neautentifikovaným útočníkom zneužiť parameter PmSess1 pre vykonávanie ľubovoľných príkazov SQL. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
Although it is not difficult to use other off-the-shelf web-shells with different extensions such as ‘ .asmx ’ or ‘ .svc ’ to use XML or JSON in the body, it would be more fun to use our old-fashion ASPX web shells such as ASPXSpy.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
APT27 ... Examples of associated tools: Ghost, ASPXSpy, ZxShell RAT, HyperBro, PlugX RAT...
Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
Initial access methods best observed have been centered around the compromise of victim web servers via n-day vulnerabilities for the deployment of webshells, including ASPXSpy, devilzshell, and Caterpillar.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2024-57968 ... umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell deployed by HAFNIUM on compromised Exchange servers for persistent access and follow-on activity.
ASP.NET web shell used by APT27 for foothold and post-exploitation on compromised servers.
ASPX webshell used to establish backdoor access on compromised VeraCore systems after chaining the two zero-day vulnerabilities.
A webshell deployed by Lebanese Cedar on compromised web servers after exploiting n-day vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.