DEWMODE is a purpose-built PHP web shell targeting Accellion File Transfer Appliance (FTA) systems. It was deployed on internet-facing FTA servers during a late-2020 to early-2021 campaign associated with Cl0p and TA505, following exploitation of multiple zero-day vulnerabilities, including the SQL injection vulnerability CVE-2021-27101.
DEWMODE interacts with the appliance’s underlying MySQL database to identify stored data and support theft of files transferred through the application. Its functionality includes database enumeration, extraction of historical transmission records, file retrieval, and compression of files for exfiltration. It also supports removal of evidence of remotely executed commands. The implant is tailored to the compromised file-transfer application rather than functioning as a general-purpose ransomware payload. Stolen information from the Accellion campaign was used to extort victim organizations through threats of public disclosure rather than encryption of their systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The syndicate chained four zero-day vulnerabilities: an unauthenticated SQL injection vulnerability via a crafted host header (CVE-2021-27101).
A server-side request forgery (SSRF) vulnerability leveraging crafted POST requests (CVE-2021-27103).
An operating system command execution flaw via a local web service call (CVE-2021-27102).
A secondary command execution vulnerability via an unauthenticated POST parameter (CVE-2021-27104).
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cl0p exploited this chain to deploy DEWMODE, a purpose-built web shell designed to evaluate internal databases, dump relational tables containing historical transmission records, and compress target files for exfiltration.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
Dewmode Backdoor: CYFIRMA identified DEWMODE web shells associated with the campaign activities.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell deployed against Accellion File Transfer Appliance systems to inspect databases, extract historical file-transfer records, and prepare files for exfiltration.
Previously referenced custom backdoor/web shell associated with Clop mass exploitation activity.
Custom web shell previously used by the Clop gang following exploitation of Accellion vulnerabilities.
A custom web shell previously deployed by Clop following exploitation of CVE-2021-27101.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.