ASPXSpy is a publicly available ASP.NET web shell used to establish persistent backdoor access on compromised Microsoft IIS web servers. It is commonly deployed after exploitation of internet-facing applications and web servers, including Microsoft Exchange and other vulnerable web applications, and enables remote command execution through the web server context. Variants and modified forms have been used by multiple intrusion sets, including China-linked groups such as APT27/BRONZE UNION/Threat Group 3390 and Gelsemium, as well as Iranian-linked actors including Agrius and Lebanese Cedar. It has also been observed in exploitation of enterprise applications such as Advantive VeraCore.
Operationally, ASPXSpy functions as a server-side web shell that allows attackers to maintain access after initial compromise, execute follow-on commands, and support broader post-exploitation activity. In observed intrusions it has been used as a foothold for reconnaissance, credential theft, lateral movement, data exfiltration, and tunneling or proxying activity via additional tooling. Threat actors have hidden or modified ASPXSpy variants to evade detection, including embedding them in seemingly benign files or deploying encoded variants.
ASPXSpy is associated primarily with espionage-oriented intrusions against government, defense, telecommunications, healthcare, education, legal, and other strategic sectors, though it has also appeared in financially motivated or disruptive operations. Its repeated use across unrelated campaigns reflects its role as an off-the-shelf post-exploitation web shell rather than a malware family exclusive to a single actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-26855: This allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange Server. The vulnerability exploits the Exchange Control Panel (ECP) via server-side request forgery (SSRF). This would also allow the attacker to gain access to mailboxes and read sensitive information. This forms the “ProxyLogon” exploit when chained with CVE-2021-27065. | Two of the vulnerabilities (CVE-2021-26855 and CVE-2021-27065) and the technique used to chain them together for exploitation have been given the name “ProxyLogon” by security company DevCore. Successful exploitation of ProxyLogon allows attackers to gain a foothold on a targeted network, potentially leading to further compromise and data exfiltration. | Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
ASPXSpy is a publicly available web shell used by several threat groups, such as Threat Group 3390 [24].
ASPXSpy is a publicly available web shell used by several threat groups, such as Threat Group 3390 [24].
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
ASPXSpy is a publicly available web shell used by several threat groups, such as Threat Group 3390 [24].
CVE-2024-57968 (CVSS skóre 9,9) Kritická zero-day zraniteľnosť Advantive VeraCore umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
CVE-2025-25181 (CVSS skóre 5,8) Zero-day zraniteľnosť v komponente timeoutWarning.asp umožňuje vzdialeným neautentifikovaným útočníkom zneužiť parameter PmSess1 pre vykonávanie ľubovoľných príkazov SQL. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
Although it is not difficult to use other off-the-shelf web-shells with different extensions such as ‘ .asmx ’ or ‘ .svc ’ to use XML or JSON in the body, it would be more fun to use our old-fashion ASPX web shells such as ASPXSpy.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT27 ... Examples of associated tools: Ghost, ASPXSpy, ZxShell RAT, HyperBro, PlugX RAT...
Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
Initial access methods best observed have been centered around the compromise of victim web servers via n-day vulnerabilities for the deployment of webshells, including ASPXSpy, devilzshell, and Caterpillar.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2024-57968 ... umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ASP.NET web shell used by APT27 for foothold and post-exploitation on compromised servers.
ASPX webshell used to establish backdoor access on compromised VeraCore systems after chaining the two zero-day vulnerabilities.
A webshell deployed by Lebanese Cedar on compromised web servers after exploiting n-day vulnerabilities.
Publicly available ASPX web shell used for post-compromise interaction with IIS/web servers; noted as previously reported in an APT 27 operation but not attribution-significant here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.