DEWMODE is a PHP web shell associated with the CL0P/Clop extortion ecosystem and activity attributed to TA505 and related financially motivated operators. It was deployed against internet-facing Accellion File Transfer Appliance servers during the large-scale exploitation of multiple zero-day vulnerabilities in late 2020 and early 2021. DEWMODE was tailored for Accellion FTA and used to interact with the appliance’s underlying MySQL database in order to steal data from compromised systems. In these intrusions, the malware supported data-theft and extortion operations rather than traditional ransomware encryption on the affected transfer appliance itself. DEWMODE is part of a broader CL0P-linked tooling set that has included other malware and web shells used across phishing-led and mass-exploitation campaigns. Its observed role was post-compromise persistence and exfiltration on vulnerable file-transfer infrastructure, contributing to high-impact breaches across multiple sectors through theft of sensitive stored data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a campaign from 2020 to 2021, TA505 used several zero-day exploits to install a web shell named DEWMODE on internet-facing Accellion FTA servers.
From late 2020 to early 2021, threat actors exploited multiple zero-day vulnerabilities in Accellion's legacy File Transfer Appliance (FTA) to install the DEWMODE web shell.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used in a Clop attack for data exfiltration.
Webshell installed on FTA servers after zero-day exploitation to support data theft and endpoint control in Clop-linked operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.