Godzilla Webshell
Godzilla Webshell is a webshell payload observed by Red Canary being deployed by adversaries exploiting Apache ActiveMQ vulnerability CVE-2023-46604 on cloud-based Linux servers.
Profile source: Mallory opens in a new tabGodzilla Webshell
Family profile
Godzilla Webshell is a webshell payload observed by Red Canary being deployed by adversaries exploiting Apache ActiveMQ vulnerability CVE-2023-46604 on cloud-based Linux servers. In the cited reporting, it is mentioned as one of several payloads delivered via continued exploitation of this nearly three-year-old flaw, alongside Ransomhub ransomware. The provided content does not describe Godzilla Webshell’s internal functionality, infection mechanism beyond post-exploitation deployment through CVE-2023-46604, specific persistence methods, or concrete indicators of compromise. High-confidence context from the reporting is that attackers continue to use the ActiveMQ vulnerability as an access vector to execute payloads including Godzilla Webshell, indicating relevance to exposed ActiveMQ environments.
Exploited software
Vulnerabilities linked to Godzilla Webshell
3 CVEsMITRE ATT&CK