WSO web shell (Web Shell by Orb) is an open-source or dual-use web shell identified in a July 2024 joint FBI-led Cybersecurity Advisory as used and/or customized by the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau threat group Andariel, also tracked as Onyx Sleet and formerly as PLUTONIUM, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. In the advisory, Andariel is described as gaining initial access primarily by exploiting public-facing web servers through known vulnerabilities, including CVE-2021-44228 (Log4Shell) and other listed CVEs, then deploying web shells to access sensitive information and applications for further exploitation. The broader campaign targets defense, aerospace, nuclear, and engineering organizations for theft of sensitive technical information and intellectual property supporting North Korea’s military and nuclear programs, with additional targeting of medical and energy sectors. The advisory does not provide WSO-specific indicators of compromise in the provided content, but places it among the open-source and dual-use tools used alongside custom implants, credential theft tools, tunneling utilities, and exfiltration tooling in Andariel intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Web Shell by Orb (WSO)
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Web Shell by Orb (WSO)
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Web Shell by Orb (WSO)
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.