
APT33-Tagged File Catalog Is Mostly Public Webshell Kits
A 20-file record attributed to APT33 turns out to be dominated by long-circulating penetration-testing webshells like php-backdoor.php, cmdasp.asp, and cmd.jsp rather than bespoke intrusion tooling. No code signing, almost no imphash, and one mislabeled security-testing plugin undercut the campaign narrative.
A record tagged to APT33 and carrying twenty file indicators turns out, on close reading, to be dominated not by a bespoke intrusion toolkit but by a corpus of long-public penetration-testing webshells — the same php-backdoor.php, cmdasp.asp, and cmd.jsp files that have circulated on GitHub archives like Webshells-main, fuzzdb-webshell, and Laudanum for well over a decade.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read