b374k is a publicly available PHP webshell used for persistent remote administration of compromised web servers. It is typically deployed after an attacker has already obtained code execution on a target, allowing continued access through a browser-based management interface. The tool has been observed on exposed command-and-control and staging infrastructure and is also commonly referenced in defensive signatures and shell-finder tooling because of its widespread criminal and intrusion-set use.
As a webshell, b374k provides post-compromise control of the underlying server and commonly supports file management, command execution, upload of additional payloads, and broader remote administration functions. Its role is primarily post-exploitation and persistence on web-accessible systems rather than initial compromise. Reporting has linked its operational use to North Korea-linked activity, including Kimsuky infrastructure management, but the malware is commodity and publicly available, so its presence alone is not sufficient for attribution.
b374k has also been observed as a follow-on payload after exploitation of vulnerable web applications, including cases where attackers abused server-side flaws to upload persistent PHP webshells. It targets PHP-capable web environments and therefore most directly affects Linux or Windows web servers running PHP applications. Because it is a server-side webshell rather than an endpoint implant, it is best characterized as a web-based backdoor used to maintain unauthorized access, execute commands, and facilitate further malicious activity on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploited vulnerability, CVE-2025-54236, is a critical improper input validation and nested deserialization flaw in the Adobe Commerce and Magento Open Source REST API, specifically affecting the /customer/address_file/upload endpoint. | This enables the upload of persistent PHP webshells, such as variants of WSO and b374k, granting attackers full remote access to the underlying server.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
공격자들은 최근까지도 'b374k' webshell 코드를 활용해 C2 서버를 운영했으며, 로그인 암호도 'victory' 문자열을 사용합니다.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Successful exploitation results in the deployment of a webshell, which is then used to enumerate the environment, extract sensitive configuration data (including database credentials and API keys), and establish additional persistence mechanisms.
rule webshell_jsp_list { ... $s2 = "out.print(\") <A Style='Color: \" + fcolor.toString() + \";' HRef='?file=\" + fn" ... } | Representative strings include "Couldn't Read directory", "while (($ekinci=readdir ($sedat))){", "File browser is under construction!", and interfaces showing file listings and navigation.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP webshell used to maintain persistent access on compromised web servers and support follow-on actions including reconnaissance, credential access, and data theft.
b374k is a remote management tool/web shell likely used by Kimsuky for remote management of malicious infrastructure.
A PHP web shell used to maintain covert access on compromised web servers.
Kimsuky 측 C2 운영에 사용된 웹셸로, Konni와 Kimsuky 간 인프라·운영 습관의 유사성을 보여주는 관련 도구로 언급됩니다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.