Microsoft said its security team detects approximately 77,000 active web shells every day, spread across 46,000 infected servers .
This number is much higher than all previous reports from the company.
For example, earlier this month, Sucuri GoDaddy's reported that it "cleaned" about 3,600 web shells from compromised sites during 2019. This number is much lower than what Microsoft.

What are web shells?
The sheer number Microsoft has revealed highlights the hackers for these tools. Web shells are considered an essential tool for every attacker, from small hacktivist groups to state-run hacking groups specializing in espionage.
Web shells are essentially malicious programs or scripts that have been installed on hacked servers.
They provide a visual interfacethat hackers can use to interact with the hacked server and its file system. Most web shells allow you to rename, copy, move, and even edit or upload files to the server. They can also steal data from the server.
Attackers usually install web shells, exploiting vulnerabilities in servers and web applications (such as CMS, CMS plugins, CMS themes, CRMs, intranets, etc.).
Web shells can be written in any programming language. This allows hackers to hide them within the code of any site. Therefore, their detection by an expert is difficult, without the help of a web firewall or a web malware scanner.
Along with the web shell, there is usually a backdoor script. Attackers compromise a server, install the web shell to interact with the filesystem, and then install a backdoor, which allows hackers to re-infect the system if the webshell is detected and removed.
The most popular web shell today is China Chopper. It was first observed in 2012 and was created by Chinese hackers. It was released on a Chinese hacking forum and adopted by cybercriminals around the world.
Microsoft warned system administrators not to ignore this threat. Hackers often use these malicious scripts to download other hacking tools to systems . These tools are, in turn, used to carry out attacks.
