ASPXSpy
MITRE ATT&CK: S0073 View on attack.mitre.org
Aliases: ASPXTool, ASPXSpy
- First seen
- 2012-05-01 00:00:00
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2025-09-30 15:24:23
- Profile updated
- 2026-07-07 12:37:04
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to ASPXSpy (S0073). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | http://aeroclubedeuberlandia.com.br/content/content/842016_165911.php | 2025-09-30 | 2 |
Detection coverage
- 23 Sigma rules
Malware & tools used
- Web Shell (attack-pattern)
Used by threat actors
- Night Dragon (campaign)
- Threat Group-3390 (threat-actor)
- Agrius (threat-actor)
- APT41 (threat-actor)
- APT39 (threat-actor)
- HAFNIUM (threat-actor)
Reports & references
- secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
- Kaspersky — 107610 (report)
- MITRE ATT&CK — G0096 (report)
- asec.ahnlab.com — 47455 (report)
- go.recordedfuture.com — Mtp 2021 1214 (report)
- recordedfuture.com — Full Spectrum Detections Five Popular Web Shells (report)
- malpedia.caad.fkie.fraunhofer.de — Php.Aspxspy (report)
- MITRE ATT&CK — S0073 (report)