DEWMODE

First seen
2020-12-15 00:00:00
Malware type
webshell
Profile updated
2026-07-07 13:46:05

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.

Reports & references

  • Mandiant — Accellion Fta Exploited For Data Theft And Extortion (report)
  • malpedia.caad.fkie.fraunhofer.de — Php.Dewmode (report)
  • accellion.com — Accellion Fta Attack Mandiant Report Full (report)
  • CISA — Ar21 055A (report)
  • go.recordedfuture.com — Mtp 2021 0312 (report)

External references