Microsoft DART Finds Web Shell Threat on the Rise
Various APT groups are successfully using Web shell attacks on a more frequent basis.
An investigation into the breach of a customer's Web server by Microsoft's Detection and Response Team (DART) found a Web shell attack that had succeeded in moving through most of the ATT&CK matrix before being remediated.
The Web shell was part of an attack that placed files in numerous directories on the Web server, gaining persistence and beginning to spread laterally in the infrastructure before it was discovered, DART notes. DART also says it is seeing Web shells used more frequently by APT groups, including Zinc, Krypton, and Gallium. And the threat is growing: "Every month, Microsoft Defender Advanced Threat Protection (ATP) detects an average of 77,000 web shell and related artifacts on an average of 46,000 distinct machines," DART says.
Read more here.
Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "C-Level & Studying for the CISSP."
About the Author
You May Also Like
DevSecOps/AWS
Oct 17, 2024Social Engineering: New Tricks, New Threats, New Defenses
Oct 23, 202410 Emerging Vulnerabilities Every Enterprise Should Know
Oct 30, 2024Simplify Data Security with Automation
Oct 31, 2024