ASPXSpy is a publicly available ASP.NET web shell used to maintain remote access to compromised Windows web servers, particularly those running Microsoft Internet Information Services (IIS). It provides a password-protected control panel supporting system-information retrieval, file creation, and process execution. Observed implementations validate access using an MD5 password hash, and attackers have modified the authentication password. The shell enables follow-on command execution through the Windows command interpreter and initially operates with the privileges of the hosting IIS application pool.
Attackers deploy ASPXSpy after exploiting public-facing web applications and servers, including on-premises Microsoft Exchange systems. It provides a persistent foothold for subsequent operations and execution of additional tools. Evasion techniques observed in deployments include Base64-encoded variants, concealment within certificate-themed text files, and placement in deeply nested website directories. Some campaigns have distributed it across hundreds of locations on hosted websites to preserve access.
ASPXSpy is used by multiple unrelated threat actors rather than being exclusive to one group. Documented users include APT27, also known as Threat Group-3390 and BRONZE UNION, which uses a modified variant called ASPXTool; HAFNIUM; APT39; Agrius; Lebanese Cedar; and XE Group. It has appeared in Exchange exploitation campaigns, intrusions affecting Korean businesses across several industries, and the Manic Menagerie campaign against web-hosting and IT providers in the United States and European Union. XE Group has also deployed it through chained vulnerabilities in Advantive VeraCore.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
The HAFNIUM threat group has been observed to use webshells including SIMPLESEESHARP, SPORTSBALL, ASPXSPY and China Chopper variants.
CVE-2021-27857: Is an insecure deserialization vulnerability in the Unified Messaging service. An attacker, authenticated either by using CVE-2021-26855 or via stolen admin credentials, could execute arbitrary code as SYSTEM on the Exchange Server.
CVE-2024-57968 (CVSS skóre 9,9) Kritická zero-day zraniteľnosť Advantive VeraCore umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
CVE-2025-25181 (CVSS skóre 5,8) Zero-day zraniteľnosť v komponente timeoutWarning.asp umožňuje vzdialeným neautentifikovaným útočníkom zneužiť parameter PmSess1 pre vykonávanie ľubovoľných príkazov SQL. | Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
Although it is not difficult to use other off-the-shelf web-shells with different extensions such as ‘ .asmx ’ or ‘ .svc ’ to use XML or JSON in the body, it would be more fun to use our old-fashion ASPX web shells such as ASPXSpy.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).
ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).
ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).
Among the web shells Veloxity said it saw deployed were China Chopper variants and ASPXSPY.
Zreťazením týchto zraniteľností získavajú útočníci schopnosť nahrávať na zraniteľné systémy webshelly ASPXSpy, čo im umožňuje vytvoriť si zadné vrátka do systému.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2024-57968 ... umožňuje vzdialeným autentifikovaným útočníkom útok typu path traversal a nahrávanie súborov do priečinkov, ktoré na to neboli určené.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell deployed by HAFNIUM on compromised Exchange servers for persistent access and follow-on activity.
ASP.NET web shell used by APT27 for foothold and post-exploitation on compromised servers.
ASPX webshell used to establish backdoor access on compromised VeraCore systems after chaining the two zero-day vulnerabilities.
A webshell deployed by Lebanese Cedar on compromised web servers after exploiting n-day vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.