Godzilla Webshell
Godzilla Webshell is a server-side webshell used for post-compromise remote control of web-accessible systems.
Profile source: Mallory opens in a new tabGodzilla Webshell
Family profile
Godzilla Webshell is a server-side webshell used for post-compromise remote control of web-accessible systems. It has been observed in intrusion activity where attackers first exploit vulnerable internet-facing applications and then deploy the webshell to execute commands, maintain access, and support follow-on operations. Reported use includes exploitation of Apache ActiveMQ vulnerability CVE-2023-46604 to execute Godzilla Webshell, as well as deployment during broader server intrusions in which operators tested multiple Chinese-language webshell frameworks after gaining code execution.
Godzilla is associated with hands-on-keyboard post-exploitation rather than initial compromise by itself. In observed incidents, operators uploaded or tested it after obtaining execution on target servers, alongside reverse shells, persistence tooling, scanners, brute-force frameworks, and lateral-movement utilities. This places it in the post-exploitation phase of attacks, where it can provide durable remote access and command execution on compromised hosts. It has appeared in campaigns affecting exposed server infrastructure, including Linux-based cloud environments and web application servers.
Available reporting supports classifying Godzilla as a webshell used for persistence and post-exploitation. Although it has been described as a Chinese webshell and has appeared in incidents involving Chinese-language tooling, its presence alone is not sufficient for reliable threat-actor attribution.
Capabilities
- Persistence
- Post Exploitation
Exploited software
Vulnerabilities linked to Godzilla Webshell
3 CVEsMITRE ATT&CK