HomeSecurityIncrease in the use of web shells by malicious actors

Increase in the use of web shells by malicious actors

shells

Malicious actors appear to be increasingly exploiting vulnerable networks to install web shells, according to a report from the US National Security Agency (NSA) and Australian Signals Directorate (ASD).

Web shells are malicious tools that can be used by hackers to gain unauthorized access to an exposed network or compromised server. It also allows them to execute remote code, download malicious payloads , and exploit other devices on the same network. 

These tools can be installed on a vulnerable server or network in various forms, such as programs specifically designed to provide web shell functionality, Perl, Ruby, Python and Unix scripts, application plugins and PHP and ASP code snippets.

Detection, prevention and mitigation of web shells

The report by the two government agencies contains a wide range of information for security teams wishing to detect hidden web shells, manage response and recovery processes after detecting web shells, and prevent malicious actors from installing such tools on vulnerable servers.

Vulnerabilities used to install web shells

Organizations are urged to patch their web applications to immediately mitigate risks from known vulnerabilities that attackers could exploit when targeting vulnerable servers.

The NSA and ASD list several security vulnerabilities that hackers commonly exploit to install malicious web shells, including Microsoft SharePoint, Citrix devices, Atlassian software, Adobe ColdFusion, Zoho ManageEngine, the WordPress Social Warfare plugin, and the Progress Telerik UI app creation tool.

About 77,000 web shells are discovered every day. The rise in web shell-based attacks these days is illustrated in a Microsoft report published in February, which states that the Microsoft Defender Advanced Threat Protection (ATP) team “detects an average of 77,000 web shells and related tools on 46,000 distinct machines.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS