DEWMODE is a custom PHP web shell associated with the Clop/CL0P extortion ecosystem and activity tracked under FIN11 and TA505-related reporting. It was notably deployed on internet-facing Accellion File Transfer Appliance servers after exploitation of multiple zero-day vulnerabilities, including CVE-2021-27101, during campaigns spanning late 2020 to early 2021. DEWMODE forms part of a broader Clop pattern of mass exploitation of managed file transfer and similar edge-facing enterprise applications followed by installation of tailored web shells for data theft and extortion operations.
DEWMODE is designed to provide remote access to compromised Accellion FTA systems and to interact with the appliance’s underlying database to identify and steal victim data. Reported functionality includes downloading files from the target and deleting evidence of remotely executed commands, supporting both exfiltration and defense evasion. In observed campaigns, operators used DEWMODE primarily to extract sensitive information rather than to establish broad follow-on intrusion across victim networks, aligning with Clop’s shift toward data-theft-led extortion.
The malware has been linked to campaigns targeting organizations across multiple sectors and geographies, including incidents affecting enterprises that relied on Accellion FTA for file transfer operations. DEWMODE is widely referenced alongside other Clop custom web shells such as LEMURLOOT, reflecting an operational model in which the threat actor develops platform-specific implants tailored to exploited products. Its role in high-profile Accellion exploitation made it a notable example of bespoke web-shell tooling used in financially motivated mass extortion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Les TTPs correspondent au schéma établi de Clop : exploitation de masse suivie de web shells personnalisés (précédents : DEWMODE pour CVE-2021-27101, LEMURLOOT pour CVE-2023-34362)
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
Les TTPs correspondent au schéma établi de Clop : exploitation de masse suivie de web shells personnalisés (précédents : DEWMODE pour CVE-2021-27101, LEMURLOOT pour CVE-2023-34362)
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The widespread primary motive of both these campaigns appear to be to the exfiltration of sensitive information... Exfiltrate design, supply chain information, sensitive information, Personally Identifiable Information (PII), Customer Identifiable Information (CII)
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously referenced custom backdoor/web shell associated with Clop mass exploitation activity.
Custom web shell previously used by the Clop gang following exploitation of Accellion vulnerabilities.
A custom web shell previously deployed by Clop following exploitation of CVE-2021-27101.
Tool used in a Clop attack for data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.