C99 is a well-known PHP web shell that became widely used in the early and mid-2000s as a post-exploitation backdoor for compromised web servers. It is designed to provide remote control over a server through a web interface, enabling attackers to execute system commands and perform a broad range of follow-on actions after initial compromise. C99 is commonly discussed alongside other classic web shells such as R57 and WSO.
As a web shell, C99 is typically deployed after attackers obtain the ability to write server-side code to a target, such as through malicious file upload, remote code execution, vulnerable web applications, or administrative abuse. Once placed on a PHP-capable server and made reachable over HTTP or HTTPS, it can provide persistent unauthorized access even if the original intrusion vector is later remediated.
C99 is associated with rich post-exploitation functionality compared with minimalist one-line shells. Reported capabilities of web shells in this class include arbitrary command execution, file management, database interaction, privilege-escalation assistance, and general remote administration of the compromised host. In intrusion chains against web applications, C99 has been used as a persistent foothold to support command execution, data theft, and broader compromise activity.
The malware targets PHP web environments and therefore runs on servers that execute PHP, most commonly on Linux-hosted web infrastructure but not exclusively. It has been observed in the context of attacks on internet-facing web applications, including cases where attackers exploited Adobe Magento flaws and then deployed PHP web shells such as C99 variants to maintain access and continue post-compromise operations.
C99 is best understood as a classic server-side web backdoor used for persistence and post-exploitation on compromised websites and application servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The SessionReaper vulnerability (CVE-2024-34102) arises from improper input validation and insecure session management within the Adobe Magento REST API. Specifically, the flaw allows an attacker to craft malicious API requests that manipulate session data stored on the server’s file system... | If successful, the attacker can inject malicious PHP code or directly upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot.
If successful, the attacker can inject malicious PHP code or directly upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A widely used PHP webshell from the early/mid-2000s that offered richer post-exploitation capabilities than simple command-execution shells.
A PHP web shell used to maintain persistent access, execute commands, and support post-exploitation activity on compromised servers.
A PHP web shell used for post-exploitation to execute commands, browse files, and maintain access on compromised web servers.
A web shell/backdoor used on compromised websites for persistent unauthorized access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.