HyperShell is a .NET web shell/backdoor associated with the Iranian threat group APT34, also known as OilRig. It is used to establish and maintain a foothold on compromised web servers, particularly Microsoft Exchange and other IIS-hosted applications, and has been linked to long-running espionage-oriented intrusions in government, energy, financial, telecommunications, and other sectors, especially in the Middle East, with additional activity observed in Asia and elsewhere.
HyperShell has been described as part of a broader cluster of APT34 server-side tooling that includes HighShell, MinionProject, and the TwoFace web shell family. Multiple reporting streams indicate that HyperShell is closely related to, or referred to by some vendors as, TwoFace. It has appeared both in operational intrusions and in the 2019 leak of APT34 tooling commonly referred to as the Lab Dookhtegan leak, which exposed several OilRig web shells and adjacent tools.
Operationally, HyperShell is used post-compromise as a persistent server-resident access mechanism. It enables attackers to execute commands and maintain remote control over hacked web infrastructure. Code overlap has been observed between HyperShell and other APT34 web shells, and later intrusions attributed with moderate confidence to Iranian operators reused code derived from HyperShell and HighShell in custom ASPX web shells deployed on compromised Exchange and SharePoint servers. HyperShell has also been associated with obscured deployment under benign-looking ASPX resources on Exchange Outlook Web Access paths, consistent with OilRig tradecraft for blending malicious server-side components into legitimate web application directories.
The malware is part of APT34’s broader intrusion ecosystem, which has relied on exploitation of internet-facing Microsoft server vulnerabilities, credential abuse, and web-shell persistence to support espionage, credential access, and follow-on operations. HyperShell itself is best characterized as a web shell used for foothold and remote command execution on compromised Windows web servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This leaked sample uses multiple WebShell backdoor programs like HighShell, HyperShell, and MinionProject, each of which is a .NET program.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware is specifically interested in the file “ExpiredPasswords.aspx” which was reported to be the name used to obscure the HyperShell backdoor used by APT34 (aka. OilRig).
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell referenced because services.aspx borrows code from it; associated with COBALT GYPSY in the reporting.
Mentioned only as another webshell/backdoor whose file name Prometei checks for and deletes on compromised Exchange servers.
A .NET webshell/backdoor used by APT34 on compromised Exchange/OWA servers for privileged access and command execution. It is described as part of the leaked toolkit and as an upgraded HighShell-related module set.
A loader associated with the TwoFace toolset and used by APT34.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.