Godzilla is a publicly available, Chinese-language webshell framework developed by BeichenDream and used for remote control of compromised web servers. Its implementations include Java/JSP and ASP.NET variants deployed on Windows and Linux systems. It supports system-command execution, file navigation and management, system-information collection, and dynamic loading of additional payloads, providing persistent access and a platform for post-exploitation activity.
Godzilla uses encrypted HTTP communications, including AES encryption and Base64 encoding in documented implementations. Java variants dynamically load attacker-supplied classes and retain payloads for execution during subsequent requests. Memory-resident deployments integrate with web-server request processing through components such as Tomcat valves or filters. ASP.NET variants can decrypt and load .NET assemblies in memory and register malicious request handlers. These techniques reduce disk artifacts and conceal malicious functionality within existing web-server processes. Some implementations frame encrypted responses with segments of an MD5-derived value.
Attackers commonly install Godzilla after exploiting internet-facing applications or abusing file-upload and deployment functionality. Documented deployment vectors include vulnerabilities in Atlassian Confluence, ManageEngine ADSelfService Plus and ServiceDesk Plus, ConnectWise R1Soft Server Backup Manager, and Telerik UI for ASP.NET AJAX. Godzilla has also been deployed on compromised JBoss and WildFly servers. It is used by multiple adversaries, including advanced persistent threat actors, rather than being exclusive to one group. Godzilla and related webshell variants have appeared in REF2924 activity and alongside tools such as Cobalt Strike and Mimikatz. Affected environments include critical infrastructure, healthcare, financial services, defense contractors, academic institutions, hosting providers, and government organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An unauthenticated actor with network access to the web interface leveraged CVE-2022-22954 to execute an arbitrary shell command as a VMware user, then exploited CVE-2022-22960 to escalate privileges to root.
CVE-2021-44077, which Zoho rated critical, is an unauthenticated remote code execution (RCE) vulnerability affecting all ServiceDesk Plus versions up to, and including, version 11305.
The advisory details the active exploitation of an authentication bypass vulnerability (CVE-2021-40539) in Zoho ManageEngine ADSelfService Plus. Its update identifies tools APT actors are using to enable this campaign.
“8220 Gang ... is an attack group targeting vulnerable Windows and Linux-based servers using the CVE-2022-26134 vulnerability.” The article also states that “Hezb is a CoinMiner recently distributed through the CVE-2022-26134 vulnerability.”
The adversary exploited R1Soft Server Backup Manager through CVE-2022-36537 in its ZK Java Framework dependency, then uploaded a malicious JDBC driver containing Godzilla web shell code. Exploitation was observed on 29 November 2022, before public proof-of-concept exploits appeared on 9 December 2022.
We observed a new attack vector of weaponization for the vulnerability CVE-2023-22527 using the Godzilla backdoor. Following initial exploitation, a loader was loaded into the Atlassian victim server which loads a Godzilla webshell.
The report lists CVE-2011-4085 among the vulnerabilities highly likely exploited through JexBoss and describes it as a regression of CVE-2010-0738.
CVE-2015-7501 is identified as a deserialization vulnerability affecting Java environments using Apache Commons Collections, including JBoss-based environments, and as highly likely exploited through JexBoss.
The CSIRT considers it highly probable that JexBoss exploited CVE-2010-0738, an improper-access-control vulnerability affecting the exposed JBoss JMX console through version 5.1.x.
The report identifies CVE-2017-12149 as remote code execution via deserialization involving JMXInvokerServlet and records numerous HTTP GET and POST requests to /invoker/JMXInvokerServlet.
CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.exe process on an IIS web server. | Ultimately, a Godzilla-style web shell was installed. The payload loads the embedded godmemshell.dll into memory and registers a malicious ASP.NET request handler.
CVE-2026-81578 is described as a pre-authentication RCE in PaperCut NG/MF's SetupCompleted API endpoint, allowing an attacker to replay initial setup and inject arbitrary code without credentials.
CVE-2026-82078 is described as a post-authentication privilege-escalation flaw in the PaperCut NG/MF scripting engine, enabling escape from the scripting sandbox and operating-system command execution as the PaperCut service account.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Mandiant and Palo Alto’s Unit42 have also reported on Behinder and Godzilla web shells deployed upon initial access in high-profile intrusions such as SonicWall, and ProxyShell.
Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla. The bug is a deserialization problem tracked as CVE-2026-5426 and can be abused without verification. It originates from the use of “shared hardcoded machine key in the web portal configuration.” | Threat actors abused a critical zero-day bug in a server that ran a KnowledgeDeliver LMS to install the Godzilla.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
Once inside, the attackers deploy web shells such as GODZILLA to maintain persistent backdoor access and execute remote commands at will.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They attempted to download web shells, including Godzilla, from likely compromised infrastructure associated with an agricultural-sector victim.
The Behinder-derived hard-coded key is also the default value when generating a shell template using the Behinder or derivative Godzilla webshell frameworks.
Their recent operations showcase advanced techniques, including the use of public-facing applications like IIS servers for initial access and the deployment of the Godzilla webshell for control.
The actor frequently, but not always, uses one or more intermediate downloader, such as an as yet unnamed PowerShell script, sLoad, Snatch, or Godzilla.
Operators scanned vulnerable ADSelfService Plus servers ... then delivered Godzilla web shells, the NGLite trojan, and the KdcSponge information stealer.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“PHANTOM PANDA leverages compromised third-party infrastructure in its operations.” The actor attempted to download web shells from infrastructure associated with an agricultural-sector victim and connect to systems associated with an automotive-sector victim to obtain tools.
A web shell provides an operator with a way to execute commands (input) and receive its results (output) on a target system.
The LNK file or document macros in turn download the next stage -- typically a PowerShell script which may download the final payload or another downloader such as sLoad.
This executable file serves as a dropper and contains an embedded, encoded Godzilla JAR file.
Elastic Security Labs observed the Microsoft .NET compiler (csc.exe) being used to compile a DLL file... Analysts who may have observed dynamic runtime compilation of .NET web shells should note that this was performed by the operator, not automatically by the system.
The second part of the JavaScript code has an object called data that contains Base64, which will be loaded as an anonymous class in-memory using sun.misc.Unsafe.
We found traces of the adversary dropping the malicious JDBC driver in {r1soft_install_location}/bin/mysql.jar on the R1Soft server.
The Godzilla-style web shell receives and executes .NET payloads through HTTP requests; the scanner also retrieves targets and communicates with Telegram over HTTP.
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
74 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A memory-resident .NET web shell deployed into a Telerik-based ASP.NET process. It accepts encrypted HTTP requests, loads and retains .NET payloads in a cookie-based session, executes requested tasks, and returns encrypted results.
An ASP.NET web shell used for persistence and likely remote command execution on compromised web servers.
Web shell deployed after exploitation to provide persistent remote access to the compromised PaperCut server.
An in-memory web shell deployed after ViewState-based remote code execution against a publicly accessible healthcare ASP.NET application. The described implementation receives .NET assemblies through an HTTP parameter, decrypts them using AES, and dynamically loads them without writing them to disk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.