Caterpillar WebShell is a web shell associated with post-compromise control and reconnaissance on Windows systems. It provides operators with remote functionality to enumerate running processes, list user accounts, obtain service information, and gather local network configuration details such as the victim host’s IP address through native system commands. The malware also includes modules for collecting information from local databases, uploading files over its command-and-control channel, modifying Windows Registry keys, scanning ports, and conducting brute-force activity against systems. These behaviors indicate use for interactive post-exploitation, internal reconnaissance, and data theft following initial compromise. The available evidence supports Caterpillar WebShell as a Windows-focused web shell used to maintain access and facilitate follow-on operations including discovery, exfiltration, and offensive network probing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
"Sandworm Team used a script to attempt RPC authentication against a number of hosts"; "Agrius engaged in various brute forcing activities via SMB"; "Chaos conducts brute force attacks against SSH services to gain initial access"; "Fox Kitten has brute forced RDP credentials"; "Turla may attempt to connect ... using net use commands and a predefined list ... of passwords."
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell capable of obtaining a list of user accounts from a victim machine.
Web shell that gathers victim IP address information using ipconfig.
Web shell capable of uploading files over its command-and-control channel.
Web shell that obtains a list of user accounts from a victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.