ASPXSpy

MITRE ATT&CK: S0073 View on attack.mitre.org

Aliases: ASPXTool, ASPXSpy

First seen
2012-05-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2025-09-30 15:24:23
Profile updated
2026-07-07 12:37:04

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to ASPXSpy (S0073). The 1 most recently updated:

TypeIndicatorUpdatedSources
URL http://aeroclubedeuberlandia.com.br/content/content/842016_165911.php 2025-09-30 2

Detection coverage

  • 23 Sigma rules

Malware & tools used

  • Web Shell (attack-pattern)

Used by threat actors

Reports & references

  • secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
  • Kaspersky — 107610 (report)
  • MITRE ATT&CK — G0096 (report)
  • asec.ahnlab.com — 47455 (report)
  • go.recordedfuture.com — Mtp 2021 1214 (report)
  • recordedfuture.com — Full Spectrum Detections Five Popular Web Shells (report)
  • malpedia.caad.fkie.fraunhofer.de — Php.Aspxspy (report)
  • MITRE ATT&CK — S0073 (report)

External references