SEASHARPEE is an Iranian-associated web shell that enables command execution on compromised systems. It can manipulate file timestamps through timestomping, providing defense-evasion and anti-forensic functionality. Its source code was leaked in March 2019 through the Lab Dookhtegan Telegram channel. In April 2019, the Chinese cyberespionage group UNC215 deployed SEASHARPEE against financial and high-technology organizations in the Middle East and Asia. Its use by UNC215 demonstrates adoption of the leaked tooling outside its original Iranian-associated context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2019, UNC215 deployed the SEASHARPEE web shell against financial and high-tech organizations in the Middle East and Asia.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell malware capable of timestomping files on victim systems.
Web shell (originally developed/used by Iranian APT actors prior to code leak) deployed for server-side access in UNC215 operations; used as part of post-exploitation tradecraft and likely for command execution and persistence on web servers.
Identified as a web shell; no specific capabilities or actor associations are stated.
Web shell used to maintain access on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.