HighShell is a .NET web shell associated with the Iranian espionage group APT34, also tracked as OilRig and Helix Kitten, and has also been mapped by some vendors to the TwoFace web shell family. It has been publicly linked to tooling exposed in the 2019 Lab Dookhtegan leaks and is part of a broader ecosystem of Exchange- and IIS-focused intrusion tooling that includes HyperShell and related server-side backdoors.
HighShell is used to maintain access on compromised Microsoft server infrastructure, particularly web-facing Microsoft Exchange and IIS environments. As a web shell, it provides remote backdoor functionality through malicious server-side code deployed on an already-compromised host. Reporting ties code derived from HighShell to later intrusions in which operators deployed web shells capable of remote code execution and file transfer operations, and used them to preserve access, move between footholds, and support follow-on credential theft and data exfiltration.
APT34 operations involving HighShell and related web shells have targeted government, financial, energy, telecommunications, and other organizations, with a concentration in the Middle East but activity also observed in Asia and elsewhere. In documented campaigns, these web shells were commonly planted on Microsoft Exchange Outlook Web Access infrastructure after exploitation of server vulnerabilities or reuse of compromised credentials. HighShell therefore fits into a broader intrusion workflow centered on persistent server-side access, post-exploitation control, and support for espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
HighShell: dubbed TwoFace by Palo Alto Networks ... This leaked sample uses multiple WebShell backdoor programs like HighShell, HyperShell, and MinionProject.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HighShell: dubbed TwoFace by Palo Alto Networks ... This leaked sample uses multiple WebShell backdoor programs like HighShell, HyperShell, and MinionProject.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell whose code overlaps with services.aspx; mentioned as a related tool associated with COBALT GYPSY but not exclusive to that group.
A full-featured C#/.NET webshell used on Exchange/Outlook OWA paths for persistence and post-compromise control. It supports authentication, file upload, command execution, and database manipulation, with newer engineered variants using modular backends.
A web-shell payload based on TwoFace and used by APT34.
A web shell attributed to APT34; source code was included in the leak.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.