Behinder, also known as Ice Scorpion, is a publicly available, open-source web-shell framework maintained by the developer rebeyond. It provides remote control of compromised web applications and servers through a Java-based operator client and server-side payloads implemented in JSP, PHP, ASP, ASPX, and C#. It supports Windows, Linux, and macOS environments and has also been deployed on enterprise appliances.
Behinder provides command execution through a virtual terminal, file upload, download and deletion, and integration with Meterpreter and Cobalt Strike. Its MemShell functionality supports injection of memory-resident web shells into application processes. Java memory-shell implementations can operate as servlet filters, decrypt attacker-supplied HTTP request data, and dynamically load and execute Java bytecode in memory. Communications use encrypted HTTP requests, including AES-encrypted and Base64-encoded payloads. Observed samples employ layered bytecode obfuscation and Unicode encoding to hinder detection and bypass web application firewalls.
Attackers generally deploy Behinder after exploiting vulnerable internet-facing applications or obtaining the ability to upload server-side code. Its web shells maintain remote access and support follow-on activity, including lateral movement. Observed deployments include z0Miner attacks against Korean WebLogic servers, cryptocurrency-mining intrusions against a Korean medical institution's Windows IIS server, and UNC2682 compromises of SonicWall Email Security systems involving access to files and emails. Behinder-generated shells have also been found on compromised Ivanti Cloud Service Appliances in Houken activity. Its public availability and use by multiple unrelated operators mean its presence alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor used WebLogic vulnerabilities such as CVE-2020-14882 to upload JSP WebShell.
CVE-2021-20022 (CVSS: 6.7): Post-authentication arbitrary file upload vulnerability. A previously authenticated threat actor may exploit this vulnerability in order to upload arbitrary files to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
On June 2nd, 2022, Atlassian disclosed a critical vulnerability impacting the Confluence collaboration tool, tracked as CVE-2022-26134; active exploitation of the vulnerability has been confirmed. CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. | Attacks observed by Volexity resulted in the deployment of the open-source webshell BEHINDER, a file upload webshell, and the China Chopper webshell.
CVE-2021-20021 (CVSS: 9.4): Unauthorized administrative account creation vulnerability. Exploitation allows a remote and unauthenticated attacker to create an administrative account by sending a crafted HTTP request to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
CVE-2021-20023 (CVSS: 6.7): Post-authentication arbitrary file read vulnerability. A previously authenticated threat actor may exploit this vulnerability in order to read arbitrary files to the remote host. | In this attack, the BEHINDER webshell was deployed to compromised assets.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | These attacks were not attributed to UAT-8616; Cisco Talos identified a total of 10 clusters of threat actors leveraging the vulnerabilities within attacks, resulting in the deployment of webshell (Godzilla, Behinder, XenShell)...
Mandiant and Palo Alto’s Unit42 have also reported on Behinder and Godzilla web shells deployed upon initial access in high-profile intrusions such as SonicWall, and ProxyShell. | Also referred to as Ice Scorpion, Behinder is publicly available and maintained by GitHub user rebeyond.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
CVE-2026-1281 + CVE-2026-1340: pre-auth RCE через bash arithmetic expansion... Обе - code injection, позволяющий неаутентифицированному атакующему выполнить произвольный код... Unit 42 фиксирует: до момента публикации 29 января 2026 уже шла активная эксплуатация. | Hadrian отмечает среди используемых Behinder - Java web shell с шифрованным каналом связи.
Cisco Talos has observed exploitation of CVE-2025-0994, a remote-code-execution vulnerability in Cityworks, a popular asset management system. The Cybersecurity and Infrastructure Security Agency (CISA) and Trimble have both released advisories pertaining to this vulnerability... | These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
Talos has found intrusions in enterprise networks of local governing bodies in the United States (U.S.), beginning January 2025 when initial exploitation first took place. UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor used a WebShell identical to that in the Github Source.
The compiled .NET webshell used an encryption key derived from "rebeyond," the developer of the Behinder webshell framework; the key is also the default value in Behinder shell templates.
On some of the compromised Ivanti CSA appliances investigated, webshells related to the open-source tool Neo-reGeorg or generated via the Behinder (“Ice Scorpion”) webshell framework were found.
These three zero-days were also actively exploited by a group Mandiant tracks as UNC2682 to backdoor systems using BEHINDER web shells, allowing them to move laterally through victims' networks and access emails and files.
These web shells consisted of multiple variations of AntSword, chinatso and Behinder along with additional generic file uploaders containing messages written in the Chinese language.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The China Chopper web shell has long been utilized post exploit to blend in network traffic, providing the attacker full command prompt access to move around the network.
The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems, allowing the operators to run arbitrary bash commands.
The sample references Java classes such as Thread.currentThread().getContextClassLoader() and ClassLoader.
CVE-2022-26134 is an unauthenticated Remote Code Execution (RCE) vulnerability that impacts all supported versions of Confluence Server and Data Center. Exploitation of this vulnerability would allow an unauthenticated and remote actor to execute code on vulnerable devices
The byte array... is the ASCII code representation of the text “System.Reflection.Assembly”. This way of presenting the code is done in order to avoid string-based detection.
Elastic Security Labs observed the Microsoft .NET compiler (csc.exe) being used to compile a DLL file... Analysts who may have observed dynamic runtime compilation of .NET web shells should note that this was performed by the operator, not automatically by the system.
final Cipher instance = Cipher . getInstance ( "AES" ); instance . init ( 2 , new SecretKeySpec ((( String ) httpServletRequest . getSession (). getAttribute ( "u" )). getBytes (), "AES" ));
What caught my eye was the in-memory web shell referred to as MemShell... The try block in Figure 7 implements MemShell
This type of webshell is widely used... by dynamically loading Java bytecode directly into memory instead of storing it on disk.
java . lang . reflect . Method defineClzMethod = clzLoader . loadClass ( "java.lang.ClassLoader" ). getDeclaredMethod ( "defineClass" , String . class , byte []. class , int . class , int . class ); defineClzMethod . setAccessible ( true ); Class clz = ( Class ) defineClzMethod . invoke ( clzLoader , clzName , bytecode , 0 , bytecode . length ); clz . newInstance ();
if ( httpServletRequest . getHeader ( "User-Agent" ) != null && httpServletRequest . getHeader ( "User-Agent" ). equals ( "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/531.26 (KHTML, like Gecko) Chrome/86.0.4240.138 Safari/531.26" ))
Figure 11: Packet capture of POST requests over port 80 Figure 12: Behinder HTTP POST request with encoded data in HTTP body
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source web shell mentioned as a comparison point for lightweight shells commonly reused by attackers.
Referenced as the model/comparison point for ORANGETAIL; not the malware primarily deployed in this incident.
A known webshell mentioned only as a comparison point for ORANGETAIL’s functionality and design.
A web shell framework referenced as the model for ORANGETAIL; mentioned for comparison rather than as the primary malware deployed in this incident.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.