Godzilla Webshell

Malware type
webshell
Family
Malware family
Profile updated
2026-07-07 13:07:15

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Context

Godzilla Webshell is a malicious shell script used to maintain access to compromised web servers. It is often employed by attackers to execute commands remotely and manage server-side operations without detection.

Reports & references

  • elastic.co — Ref2924 Howto Maintain Persistence As An Advanced Threat (report)
  • asec.ahnlab.com — 47455 (report)
  • Trend Micro — The Espionage Toolkit Of Earth Alux (report)
  • malpedia.caad.fkie.fraunhofer.de — Jsp.Godzilla Webshell (report)
  • blog.gigamon.com — Investigating Web Shells (report)
  • Palo Alto Unit 42 — Tiltedtemple Manageengine Servicedesk Plus (report)
  • Palo Alto Unit 42 — Manageengine Godzilla Nglite Kdcsponge (report)
  • Microsoft — Tarrask Malware Uses Scheduled Tasks For Defense Evasion (report)
  • harfanglab.io — Insights Ivanti Csa Exploitation (report)

External references