216.73.217.22

JSPSpy and 'Filebroser': A Custom File Management Tool in Webshell Infrastructure

· Published 12/03/2025 14:52 · Modified 12/03/2025 16:25

Export JSON

Essential information

Published
12/03/2025 14:52
Modified
12/03/2025 16:25
Tags
2025-03-12 detection file management filebroser http headers infrastructure jspspy remote access web shell
Related entities
4 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware, 2 others

Description

Researchers have identified a cluster of servers featuring '', a modified version of the open-source File Browser project. The spans multiple hosting providers in China and the United States, using both cloud services and traditional ISPs. , a Java-based first observed in 2013, has been used by various threat actors, including the Lazarus Group. The servers typically host on port 80, with one instance on port 8888. Two servers also host the '' login panel on port 8001. strategies for include analyzing login page titles and HTTP response headers. The presence of '' alongside raises questions about its purpose in attack operations.

External references