C99 is a well-known PHP webshell family that became widely used in the early and mid-2000s as a post-exploitation implant on compromised web servers. It is typically deployed after attackers obtain the ability to upload or write server-side code through vulnerabilities, stolen credentials, or administrative abuse. Once installed, it provides a browser-accessible interface for remote command execution and broader control of the hosting environment.
C99 is associated with classic webshell tradecraft on PHP-based servers and is commonly grouped with other prominent families such as r57, WSO, and c66. Variants and derivatives have appeared in many public malware collections and detection rule sets, reflecting long-term reuse, modification, and repackaging by multiple threat actors rather than exclusive use by a single group.
Its functionality commonly includes command execution, file browsing and manipulation, file upload, and general server administration features that support follow-on intrusion activity. In operational use, such capabilities enable attackers to maintain persistence on a compromised web application server, conduct reconnaissance of the local environment, stage additional payloads, and perform post-exploitation actions. Webshells in this class are also routinely used to facilitate data theft and, depending on the surrounding environment and privileges, can support lateral movement or privilege escalation through native system tools and misconfigurations.
C99 primarily targets and runs on PHP-enabled web servers, most commonly in Linux hosting environments, though the decisive platform characteristic is the presence of a PHP-capable web stack. It is best characterized as a server-side web backdoor used for persistent unauthorized access after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The SessionReaper vulnerability (CVE-2024-34102) arises from improper input validation and insecure session management within the Adobe Magento REST API. Specifically, the flaw allows an attacker to craft malicious API requests that manipulate session data stored on the server’s file system... | If successful, the attacker can inject malicious PHP code or directly upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot.
If successful, the attacker can inject malicious PHP code or directly upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...upload webshells, such as variants of WSO, C99, or custom lightweight shells, into the webroot."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A widely used PHP webshell from the early/mid-2000s that offered richer post-exploitation capabilities than simple command-execution shells.
A PHP web shell used to maintain persistent access, execute commands, and support post-exploitation activity on compromised servers.
A PHP web shell used for post-exploitation to execute commands, browse files, and maintain access on compromised web servers.
A web shell/backdoor used on compromised websites for persistent unauthorized access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.