# T1505.003 Web Shell

> As of 2026-10-05, T1505.003 (Web Shell) appears in 170 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including GhostEmperor, Storm-2603, Cl0p; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 170 (114 critical, 47 high, 9 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 43
- **Detection rules:** 564 (counts only; Blue tier and above)

## Key facts

- **ID:** T1505.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Parent:** T1505
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1505/003/

## Activity timeline

T1505.003 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 61 reports, and 169 of the 170 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1505.003 Web Shell is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix, as a sub-technique of [T1505 Server Software Component](https://intel.threadlinqs.com/technique/T1505). Threadlinqs maps 170 of 2623 tracked threats (6.5%) to it; by severity that is 114 critical, 47 high, 9 medium.

Threats that use T1505.003 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (156 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (103 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (101 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (87 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (84 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

43 tracked threat actors appear in the threats that use T1505.003; the most frequent are [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (4), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) (4), [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) (3), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (3), [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) (3).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1505.003.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1505.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Process — Process Creation

## Threat actors using it

- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 4
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 4
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 3
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3
- [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Head Mare](https://intel.threadlinqs.com/actor/Head%20Mare) — 2
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2
- [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686) — 2

## Tracked threats

The 30 most recent of 170 tracked threats that use T1505.003.

- [CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2896) — high — 2026-10-04
- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)](https://intel.threadlinqs.com/threat/TL-2026-2823) — critical — 2026-10-01
- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…](https://intel.threadlinqs.com/threat/TL-2026-2690) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)](https://intel.threadlinqs.com/threat/TL-2026-2682) — high — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…](https://intel.threadlinqs.com/threat/TL-2026-2678) — critical — 2026-09-26
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21
- [Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link](https://intel.threadlinqs.com/threat/TL-2026-2587) — critical — 2026-09-19
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively…](https://intel.threadlinqs.com/threat/TL-2026-2539) — critical — 2026-09-16
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15

## Related CVEs

CVEs referenced by the tracked threats that use T1505.003, most frequent first.

- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-56291](https://intel.threadlinqs.com/cve/CVE-2026-56291)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)

## Detection coverage

Threadlinqs maintains 564 detection rules mapped to T1505.003 (SPL 213, KQL 166, Sigma 185). Rule content is available to Blue tier accounts and above; this page shows counts only.

564 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1505 Server Software Component](https://intel.threadlinqs.com/technique/T1505) — 265 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1505.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
