JexBoss is an open-source exploitation tool and webshell framework used to identify and compromise vulnerable JBoss application servers and related Java web platforms. It is commonly associated with exploitation of exposed management and application interfaces and has been linked in reporting to exploitation activity involving Apache Struts vulnerability CVE-2017-5638, as well as broader intrusion activity against internet-facing JBoss environments. Detected artifacts include JSP- and WAR-based server-side components, indicating use as a deployable webshell or post-exploitation implant on compromised Java application servers.
Operationally, JexBoss is used to scan for exposed or vulnerable services, attempt exploitation, and establish server-side access that can support follow-on actions. Its role is typically post-compromise enablement on web infrastructure rather than commodity endpoint malware deployment. Security reporting has noted its use as part of intrusion chains that begin with reconnaissance of JBoss-related paths and services and proceed to unauthorized access and remote code execution on vulnerable servers. It has also appeared among open-source tools used by advanced threat operators, including activity documented under Operation Wocao.
JexBoss primarily targets Java enterprise server environments running on web application infrastructure. Because it is deployed as server-side Java web content, it is best characterized as a webshell-oriented backdoor capability for compromised servers, enabling persistent remote interaction and further post-exploitation activity on affected systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-5638 Vulnerable Products: Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 Associated Malware: JexBoss Mitigation: Upgrade to Struts 2.3.32 or Struts 2.5.10.1 | CVE-2017-5638 ... Associated Malware: JexBoss
9 distinct techniques documented for this family, organized by ATT&CK tactic.
These searches help detect evidence of these attacks... This Analytic Story looks for probing and exploitation attempts targeting JBoss application servers.
During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints. APT28 has performed large-scale scans in an attempt to find vulnerable servers. APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.
Annotations ID Technique Tactic T1133 External Remote Services Initial Access Delivery Exploitation Installation
An arbitrary code execution vulnerability in Citrix VPN appliances, known as CVE-2019-19781, has been detected in exploits in the wild. An arbitrary file reading vulnerability in Pulse Secure VPN servers, known as CVE-2019-11510, continues to be an attractive target for malicious actors.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
Annotations ID Technique Tactic T1133 External Remote Services Initial Access Delivery Exploitation Installation
Descriptions repeatedly identify server-side implants such as "Web shell - file ASPXspy2.aspx", "Detects a ASPX web shell", "Detects JexBoss JSPs", and "Webshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of it". | The content is a large YARA ruleset explicitly focused on web shells, e.g. rule names and descriptions such as "Webshell_Insomnia", "JSP_Browser_APT_webshell", "WEBSHELL_ASPX_Mar21_1", and "Detects a tiny webshell - chine chopper".
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used to exploit vulnerable JBoss servers, potentially enabling unauthorized access, arbitrary code execution, or privilege escalation.
Tool used to target/exploit JBoss application servers (referenced as obtained/used in the operation).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.