FILEMembers
FILE

APT33-Tagged File Catalog Is Mostly Public Webshell Kits

A 20-file record attributed to APT33 turns out to be dominated by long-circulating penetration-testing webshells like php-backdoor.php, cmdasp.asp, and cmd.jsp rather than bespoke intrusion tooling. No code signing, almost no imphash, and one mislabeled security-testing plugin undercut the campaign narrative.

Jul 13, 2026, 05:44 (UTC+9)Last seenJul 13, 2026Severity78ByCTX TeamActorAPT33MagnalliumIOC32MITRE7

A record tagged to APT33 and carrying twenty file indicators turns out, on close reading, to be dominated not by a bespoke intrusion toolkit but by a corpus of long-public penetration-testing webshells — the same php-backdoor.php, cmdasp.asp, and cmd.jsp files that have circulated on GitHub archives like Webshells-main, fuzzdb-webshell, and Laudanum for well over a decade.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence