Skip to content
Malware family

Godzilla Webshell

Godzilla Webshell is a webshell payload observed by Red Canary being deployed by adversaries exploiting Apache ActiveMQ vulnerability CVE-2023-46604 on cloud-based Linux servers.

Profile source: Mallory opens in a new tab

Godzilla Webshell

Family profile

Godzilla Webshell is a webshell payload observed by Red Canary being deployed by adversaries exploiting Apache ActiveMQ vulnerability CVE-2023-46604 on cloud-based Linux servers. In the cited reporting, it is mentioned as one of several payloads delivered via continued exploitation of this nearly three-year-old flaw, alongside Ransomhub ransomware. The provided content does not describe Godzilla Webshell’s internal functionality, infection mechanism beyond post-exploitation deployment through CVE-2023-46604, specific persistence methods, or concrete indicators of compromise. High-confidence context from the reporting is that attackers continue to use the ActiveMQ vulnerability as an access vector to execute payloads including Godzilla Webshell, indicating relevance to exposed ActiveMQ environments.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 22, 2026
Last activity
Jul 22, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • CN1

Leading providers

  • Huawei Cloud Service data center1

Infrastructure traits

  • Hosting 1

Exploited software

Vulnerabilities linked to Godzilla Webshell

3 CVEs

MITRE ATT&CK

Godzilla Webshell in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.