AntSword is an open-source Chinese web shell management framework widely used to control compromised web servers. The name also commonly refers to server-side web shells and variants operated through the framework. Its virtual terminal enables remote command execution, allowing attackers to administer compromised hosts, conduct reconnaissance, download and execute additional payloads, and maintain backdoor access. PHP and JSP web shells associated with AntSword have been observed in intrusions involving IIS and Apache Tomcat servers.
Attackers deploy or operate AntSword-compatible shells after exploiting vulnerable or misconfigured public-facing applications. Observed intrusion paths include exploitation of the Trimble Cityworks remote code execution vulnerability CVE-2025-0994 and abuse of an exposed, unauthenticated phpMyAdmin interface. In the latter case, attackers poisoned MariaDB query logs to create a PHP evaluation backdoor and subsequently controlled it through AntSword. AntSword has supported deployment of additional tooling, including the Nezha monitoring agent and the DUSTPAN dropper.
AntSword usage has been observed in operations involving APT41, APT15, UAT-6382, and CL-UNK-1068. These operations include persistence, lateral movement, and data theft, with victims spanning Asian critical infrastructure, government, technology, telecommunications, and media organizations, as well as local government networks in the United States. Its public availability and use by multiple operators mean that AntSword alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers have been leveraging a Cityworks RCE vulnerability (CVE-2025-0994) to get access to the targeted environments and perform the initial reconnaissance.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
Observed unknown threat actors exploiting a vulnerability in SharePoint described in CVE-2019-0604 to install several webshells on the website of a Middle East government organization... publicly available exploit code suggests that CVE-2019-0604 is still a major attack vector. | "One of these webshells is the open source AntSword webshell freely available on Github, which is remarkably similar to the infamous China Chopper webshell."
"...a signature trait of C2 tools like China Chopper or AntSword."
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once compromised the threat actors deploy various web shells such as AntSword and chinatso/Chopper, used later to spread the backdoors.
In recent campaigns, ANTSWORD and BLUEBEAM web shells were seen on exposed Tomcat Apache Manager server to execute certutil.exe and download the DUSTPAN dropper.
"One of these webshells is the open source AntSword webshell freely available on Github, which is remarkably similar to the infamous China Chopper webshell."
Web shells – AntSword, Behinder, China Chopper, Godzilla , giving the hackers backdoor access to the breached systems.
We observed the attackers deploying the GodZilla web shell, and a variation of AntSword
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Each of these POST requests represents the attacker’s C2 server sending instructions to the compromised web server via the deployed web shell.
Web shells were used to execute certutil.exe and download the DUSTPAN dropper; DUSTTRAP may download additional plugins.
The access afforded by the ANTSWORD web shell is then used to run the "whoami" command to determine the privileges of the web server and deliver the open-source Nezha agent, which can be used to remotely commandeer an infected host by connecting to an external server
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell used by the Chinese threat cluster CL-UNK-1068 after initial compromise to move laterally to additional hosts and SQL servers.
Webshell used to maintain access and conduct post-exploitation actions such as lateral movement and data theft/exfiltration.
Web shell used for command execution and persistence on compromised web servers.
A web shell management tool used to control web shells on compromised servers and support post-exploitation operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.