Godzilla is a widely used post-exploitation web shell and related offensive framework most commonly associated with compromised web applications and IIS-hosted ASP.NET environments, though Java-based variants and workflows are also documented. It is frequently deployed after exploitation of public-facing applications, including Exchange, ADSelfService Plus, KnowledgeDeliver, and other vulnerable web platforms, where it provides attackers with durable remote control over compromised servers. Godzilla is regularly observed alongside other intrusion tooling such as Cobalt Strike and is used by both espionage-oriented and financially motivated operators.
The framework is known for encrypted command-and-control communications, including XOR-protected traffic in some observed deployments, and for designs that load code directly into memory rather than relying solely on disk-resident artifacts. Java-oriented implementations have been noted for dynamically loading bytecode in memory, a pattern shared with other advanced web shells. In operational use, Godzilla enables command execution and broader post-compromise control, and it is commonly treated as a foothold mechanism that supports follow-on payload delivery, privilege escalation, persistence, credential access, and lateral activity through additional tools.
Godzilla has been observed in intrusions attributed to multiple China-linked threat clusters and in broader criminal exploitation ecosystems. Reported users or associated operators include APT27, TeleBoyi, and Earth Baku, and the tool also appears repeatedly in Chinese-speaking underground and intrusion workflows alongside tools such as VShell, Behinder, and SNOWLIGHT. It has featured in high-profile exploitation waves involving ProxyShell, SonicWall-related intrusions, Zoho ManageEngine ADSelfService Plus exploitation, and attacks abusing exposed or hard-coded ASP.NET machine keys to conduct ViewState deserialization and remote code execution.
Delivery and installation are context-dependent. In server intrusions, Godzilla is commonly written to compromised web roots as a web shell after exploitation of internet-facing applications. In malware-delivery ecosystems, the name has also been used for an intermediary loader stage that downloads additional payloads, including banking malware, and it has appeared in multi-stage chains involving PowerShell, VBS, cracked-software lures, and other loaders. Because the supplied facts describe both a web-shell framework and loader usage under the same name, the strongest high-confidence characterization is as a web shell used for post-exploitation control of compromised servers, especially Windows IIS and ASP.NET targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant and Palo Alto’s Unit42 have also reported on Behinder and Godzilla web shells deployed upon initial access in high-profile intrusions such as SonicWall, and ProxyShell.
In 2021, APT27 targeted multiple industries... by exploiting REST API authentication bypass in Zoho ManageEngine ADSelfService Plus (CVE-2021-40539), resulting in the compromise of at least nine organizations worldwide. Operators scanned vulnerable ADSelfService Plus servers... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer. | Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla. The bug is a deserialization problem tracked as CVE-2026-5426 and can be abused without verification. It originates from the use of “shared hardcoded machine key in the web portal configuration.” | Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
Following the exploitation of these CVEs, the threat actor deployed a variant of the Godzilla web shell under the filename “20251117022131.jsp”.
We observed the vulnerability exploited to download webshells, including: ... The Godzilla Webshell that has also been used in previous campaigns exploiting other vulnerabilities.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
A torrent of proof-of-concept (PoC) exploits for React2Shell has hit the internet following the vulnerability's disclosure last week, and while security researchers say most are fake, ineffective and AI-generated slop, some have proven to be quite dangerous. CVE-2025-55182 was disclosed on Dec. 3 with a maximum CVSS score of 10, setting off urgent calls for immediate mitigation. The remote code execution (RCE) flaw stems from an unsafe deserialization issue in React Server Components (RSC) protocol that affects not only React open source software but other frameworks such as Next.js. The critical vulnerability came under exploitation shortly after public disclosure, with Amazon threat intelligence observing attacks from several China-nexus threat groups. Attacks against the vulnerability, which researchers refer to as "React2Shell," increased this week as opportunistic threat actors of all stripes launched campaigns with cryptominers, infostealers, backdoors, and more.
The content states CVE-2023-46604 (Apache ActiveMQ) “was known to have been used in the Godzilla ransomware attack.”
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their recent operations showcase advanced techniques, including the use of public-facing applications like IIS servers for initial access and the deployment of the Godzilla webshell for control.
The actor frequently, but not always, uses one or more intermediate downloader, such as an as yet unnamed PowerShell script, sLoad, Snatch, or Godzilla.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
Following successful exploitation, operators deployed GODZILLA web shells into Exchange and IIS directories to establish persistent remote access.
Web shells – AntSword, Behinder, China Chopper, Godzilla , giving the hackers backdoor access to the breached systems.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Specifically, the warrants authorized the seizures of computer servers that launched and controlled the DDoS attacks, computer servers that relayed attack commands to a broader network of attack computers, and accounts containing the source code for the DDoS tools used by Anonymous Sudan.
Once running, it can browse and manage files, execute OS or PHP code, spin up reverse shells
The LNK file or document macros in turn download the next stage -- typically a PowerShell script which may download the final payload or another downloader such as sLoad.
Monitor for unusual child processes spawned by w3wp.exe . Commands observed include: cmd.exe /c ... whoami
On March 19, we detected a targeted email with a Microsoft Word attachment... that used an Xbagging (aka Bartallex) downloader macro.
Microsoft varovala pred útokmi na aplikácie ASP.NET, v rámci ktorých útočníci na vzdialené vykonanie kódu ... zneužívajú verejne dostupné statické strojové kľúče (machine keys) ASP.NET.
A known indicator associated with the campaign includes the BLUEBEAM payload “LoadLibrary.dll” with SHA-256 hash 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2.
According to the indictment and a criminal complaint also unsealed today, since early 2023, the Anonymous Sudan actors and their customers have used the group’s Distributed Cloud Attack Tool (DCAT) to conduct destructive DDoS attacks and publicly claim credit for them. In approximately one year of operation, Anonymous Sudan’s DDoS tool was used to launch over 35,000 DDoS attacks.
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell/tool mentioned as part of the tooling ecosystem associated with Chinese-speaking operators, but not described as central to this campaign.
A webshell/tooling family mentioned only as part of tradecraft associated with Chinese-speaking forums.
A webshell framework used alongside the primary shell in the campaign, notable here for XOR-encrypted command-and-control traffic.
A webshell framework/tooling family referenced as part of the operator’s exploitation and shell-management workflow.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.