Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

TwoFace Webshell: Persistent Access Point for Lateral Movement

released on 2017-08-05 @ 07:01:24 PM
While investigating a recent security incident, Unit 42 found a webshell that we believe was used by the threat actor to remotely access the network of a targeted Middle Eastern organization. The construction of the webshell was interesting by itself, as it was actually two separate webshells: an initial webshell that was responsible for saving and loading the second fully functional webshell. It is this second webshell that enabled the threat actor to run a variety of commands on the compromised server. Due to these two layers, we use the name TwoFace to track this webshell.