GhostWebShell is an ASP.NET web shell that provides remote command execution and persistent access to compromised Windows web servers. It embeds a Base64-encoded ASP.NET page that accepts attacker-supplied commands through an HTTP query parameter, executes them using the Windows command interpreter, and returns standard output and standard error as HTML-formatted responses. It uses reflection to temporarily modify internal ASP.NET BuildManager flags, bypass application precompilation checks, and register a custom VirtualPathProvider. This allows a malicious page to be supplied from memory or a nonstandard location and exposed through an apparently legitimate application path. GhostWebShell executes the injected page through ASP.NET server functionality, restores the original flags to reduce its footprint, and communicates exceptions through a custom HTTP response header.
GhostWebShell has been deployed following exploitation of on-premises Microsoft SharePoint servers through the ToolShell vulnerability chain, involving CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. It has also been found on an internet-facing web server during a Medusa ransomware intrusion, where web shells maintained access after exploitation of a vulnerable public-facing application. GhostWebShell code from the ysoserial utility is incorporated into GhostContainer, a separate modular backdoor deployed by NightEagle, also known as APT-Q-95, on Microsoft Exchange servers in attacks against Russian businesses.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors are combining two previously patched vulnerabilities (CVE-2025-49704 and CVE-2025-49706) with two fresh, zero-day variants (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution.
This attack leverages a newly identified exploit chain dubbed "ToolShell." Threat actors are combining two previously patched vulnerabilities (CVE-2025-49704 and CVE-2025-49706) with two fresh, zero-day variants (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution. | Threat actors are combining two previously patched vulnerabilities (CVE-2025-49704 and CVE-2025-49706) with two fresh, zero-day variants (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution.
Threat actors are combining two previously patched vulnerabilities (CVE-2025-49704 and CVE-2025-49706) with two fresh, zero-day variants (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution.
Threat actors are combining two previously patched vulnerabilities (CVE-2025-49704 and CVE-2025-49706) with two fresh, zero-day variants (CVE-2025-53770 and CVE-2025-53771) to achieve remote code execution.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GhostContainer ... includes elements connected to the Neo-reGeorg tunnel, code for CVE-2020-0688, and the GhostWebShell class.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named web-shell component/class included in the GhostContainer Exchange backdoor.
A web-shell component/class included in the GhostContainer backdoor's public-component assembly.
Web-shell component incorporated into GhostContainer.
An ASP.NET web shell observed in the ongoing SharePoint exploitation wave. It accepts arbitrary commands through a ?cmd= parameter, executes them through cmd.exe, and returns standard output and error over HTTP. It manipulates BuildManager flags and registers a custom VirtualPathProvider to bypass precompilation checks and serve an injected page from memory or a non-standard location under a legitimate-looking SharePoint path. It restores modified flags and hides exceptions in an HTTP header to reduce detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.