Skip to content

Godzilla Webshell

Godzilla Webshell is a server-side webshell used for post-compromise remote control of web-accessible systems.

Profile source: Mallory opens in a new tab

Godzilla Webshell

Family profile

Godzilla Webshell is a server-side webshell used for post-compromise remote control of web-accessible systems. It has been observed in intrusion activity where attackers first exploit vulnerable internet-facing applications and then deploy the webshell to execute commands, maintain access, and support follow-on operations. Reported use includes exploitation of Apache ActiveMQ vulnerability CVE-2023-46604 to execute Godzilla Webshell, as well as deployment during broader server intrusions in which operators tested multiple Chinese-language webshell frameworks after gaining code execution.

Godzilla is associated with hands-on-keyboard post-exploitation rather than initial compromise by itself. In observed incidents, operators uploaded or tested it after obtaining execution on target servers, alongside reverse shells, persistence tooling, scanners, brute-force frameworks, and lateral-movement utilities. This places it in the post-exploitation phase of attacks, where it can provide durable remote access and command execution on compromised hosts. It has appeared in campaigns affecting exposed server infrastructure, including Linux-based cloud environments and web application servers.

Available reporting supports classifying Godzilla as a webshell used for persistence and post-exploitation. Although it has been described as a Chinese webshell and has appeared in incidents involving Chinese-language tooling, its presence alone is not sufficient for reliable threat-actor attribution.

Capabilities

  • Persistence
  • Post Exploitation

Exploited software

Vulnerabilities linked to Godzilla Webshell

3 CVEs

MITRE ATT&CK

Godzilla Webshell in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.