Awen is a custom ASP.NET web shell used to provide persistent remote access and post-compromise command execution on compromised servers. The content directly associates Awen with Volt Typhoon, which has deployed it alongside other custom web shells such as VersaMem, AuditReport, and iisstart.aspx. One observed Volt Typhoon variant of Awen used AES encryption and decryption for command-and-control communications. Awen has also been observed in exploitation of Microsoft SharePoint CVE-2019-0604 against a Middle East government organization in September 2019, where unknown threat actors deployed an Awen ASP.NET web shell variant to c.aspx on the SharePoint server. In that intrusion, the Awen sample had SHA256 5d4628d4dd89f31236f8c56686925cbb1a9b4832f81c95a4300e64948afede21. After deployment, the actors used Awen to run discovery commands including whoami, query user, net group, net localgroup administrators, ipconfig /all, and ping. High-confidence context in the content links Awen to stealthy post-exploitation activity, persistent access on internet-facing enterprise applications, and use by PRC-linked Volt Typhoon as well as separate unattributed SharePoint compromises affecting a Middle East government target.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"The result of this entire command saves a variant of the Awen asp.net webshell ... to the SharePoint server to further interact with the compromise server."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also deploys custom web shells like Awen, VersaMem, AuditReport, and iisstart.aspx, further enabling persistent remote access and control.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ASP.NET webshell used immediately after SharePoint exploitation to execute commands for host/network discovery and to stage/deploy a second webshell (AntSword variant) via base64 + certutil decoding.
Custom web shell used by Volt Typhoon to maintain persistent remote access and control in victim environments.
Web shell used for command-and-control communications with AES-based encryption/decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.