Analysts named this unique finding the JOMANGY webshell. According to the official report, “JOMANGY is a PHP webshell family with no prior public documentation”.
JOMANGY
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to JOMANGY
2 CVEsMITRE ATT&CK
JOMANGY in ATT&CK
17 distinct techniquesTechniques
17 techniques T1037.004 RC Scripts T1053.003 Cron T1190 Exploit Public-Facing Application T1685 Disable or Modify Tools T1505.003 Web Shell T1027 Obfuscated Files or Information T1070 Indicator Removal T1083 File and Directory Discovery T1136 Create Account T1222 File and Directory Permissions Modification T1071 Application Layer Protocol T1059 Command and Scripting Interpreter T1037 Boot or Logon Initialization Scripts T1057 Process Discovery T1136.001 Local Account T1564.001 Hidden Files and Directories T1059.006 Python