WSO, short for Web Shell by Orb, is a widely used PHP web shell that provides attackers with browser-based remote administration of compromised web servers. It is commonly deployed after exploitation of vulnerable internet-facing applications or file upload flaws and is frequently observed on compromised PHP environments. WSO is designed to give an operator persistent access to the underlying server through a web interface that supports command execution, file management, and broader post-compromise administration. Variants are often disguised to blend into legitimate web content and can masquerade as error pages with hidden authentication prompts to reduce suspicion.
WSO is associated with opportunistic intrusions as well as targeted operations. It has been observed in campaigns attributed to state-linked and advanced threat actors, including activity associated with Lazarus-linked intrusion sets and Energetic Bear, where it was used on compromised public-facing servers as part of broader attack infrastructure. In such operations, WSO has supported persistence on web servers, remote control of hosted environments, and follow-on actions such as credential collection, staging of additional tooling, and use of compromised servers for watering-hole or other secondary attacks.
The shell’s core functionality aligns with classic web shell behavior: remote command execution, directory browsing, file upload and download, file editing, permission changes, and general server-side administration. In practice, this enables attackers to maintain access, manipulate hosted content, deploy additional payloads, and exfiltrate data from the compromised environment. WSO is also commonly referenced in defensive detection content and malware signature sets because of its prevalence, numerous variants, and repeated use across both criminal and espionage-motivated intrusions targeting web infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This enables the upload of persistent PHP webshells, such as variants of WSO and b374k, granting attackers full remote access to the underlying server. | The exploited vulnerability, CVE-2025-54236, is a critical improper input validation and nested deserialization flaw in the Adobe Commerce and Magento Open Source REST API, specifically affecting the /customer/address_file/upload endpoint.
The SessionReaper vulnerability (CVE-2024-34102) arises from improper input validation and insecure session management within the Adobe Magento REST API. Specifically, the flaw allows an attacker to craft malicious API requests that manipulate session data stored on the server’s file system... | If successful, the attacker can inject malicious PHP code or directly upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WSO is a popular web shell and file manager (it stands for “Web Shell by Orb”) that has the ability to masquerade as an error page containing a hidden login form.
"...upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP web shell used to provide persistent remote access and command execution on compromised web servers.
A PHP webshell used to provide persistent remote access to compromised servers, enabling post-exploitation activity such as environment enumeration, data extraction, and persistence.
A web shell/backdoor family commonly deployed on compromised websites to maintain unauthorized access and later discovered by shell finder tools.
A web shell used for remote administration of compromised machines, with file management capability and the ability to masquerade as an error page with a hidden login form.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.