DEWMODE
- First seen
- 2020-12-15 00:00:00
- Malware type
- webshell
- Profile updated
- 2026-07-07 13:46:05
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
Reports & references
- Mandiant — Accellion Fta Exploited For Data Theft And Extortion (report)
- malpedia.caad.fkie.fraunhofer.de — Php.Dewmode (report)
- accellion.com — Accellion Fta Attack Mandiant Report Full (report)
- CISA — Ar21 055A (report)
- go.recordedfuture.com — Mtp 2021 0312 (report)