Analysis of a Large-Scale Adobe ColdFusion Campaign Deploying Webshells to 4,244 URLs
By Threat Intelligence Unit
Overview
Oasis Security identified a large-scale campaign targeting internet-facing Adobe ColdFusion servers by exploiting CVE-2023-26360.
Analysis of collected attacker infrastructure revealed the complete attack workflow, including the exploitation script used to deploy command-execution webshells, records of 4,244 successfully compromised URLs, and categorized victim lists spanning government, higher education, nonprofit, and commercial organizations across multiple countries.
Of the recorded webshells, 398 remained accessible during analysis, indicating that some affected organizations may still be exposed.
Executive Summary
- Analysis of attacker infrastructure identified a large-scale campaign exploiting the Adobe ColdFusion vulnerability CVE-2023-26360 to deploy command-execution webshells
- Collected attacker files confirmed 4,244 successfully compromised URLs spanning government, higher education, nonprofit, and commercial organizations across multiple countries
- Of the recorded webshells, 398 remained accessible during analysis, leaving some affected organizations exposed through the deployed command-execution webshells
Infrastructure Analysis
Server-side files were collected from infrastructure hosted at the following server:
- IP Address:
47.237.103.207 - Geolocation: Singapore
- Hosting Provider: Alibaba Cloud
Analysis of the collected files revealed multiple artifacts associated with the attacker's operation, including:
- The exploitation script used to deploy the webshells
- A list of 4,244 compromised URLs
- Separate files categorizing government and education victims
The collected files indicate that the operator maintained structured records of successfully compromised systems and organized high-value targets by sector.
Attack Analysis
The operator exploited an Adobe ColdFusion remote code execution vulnerability to upload command-execution webshells to a large number of internet-facing servers, successfully compromising 4,244 URLs.
The campaign leveraged CVE-2023-26360, an unauthenticated Adobe ColdFusion remote code execution vulnerability caused by deserialization of untrusted data. The vulnerability has been actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.
Exploitation Script
Analysis of the collected files identified a custom Python script named exp.py, which automated exploitation across numerous target URLs.
The script exploited a vulnerable ColdFusion server by uploading command-execution webshells using CVE-2023-26360. The webshell payload was stored within the script as a Base64-encoded string in the payloadEnd variable and decoded at runtime before being delivered to each target.
Figure 1. exp.py exploit script with Base64 webshell payload
Webshell Analysis
Decoding the payloadEnd value revealed the ColdFusion webshell.
The webshell provides a simple command-execution interface consisting of two input fields:
c— Specifies the executable programo— Specifies the command-line arguments passed to the program
When submitted, the webshell executes the supplied command through the ColdFusion cfexecute tag and returns the output directly within the web interface.
Successful exploitation results were automatically written to result2.txt, which records the full URL of each uploaded webshell.
The operator additionally categorized compromised URLs into separate files:
gov.txt— Government-related organizationsedu.txt— Education-related organizations
These files indicate that the operator separately tracked organizations considered to be of higher interest.
Figure 2. Decoded ColdFusion webshell using cfexecute
Victim Analysis
Analysis of result2.txt identified 4,244 URLs where the webshell was successfully uploaded.
The collected data indicates that the operator maintained separate records for organizations considered to be of higher interest by categorizing compromised targets into two sector-specific files:
gov.txt— Government-related organizationsedu.txt— Education-related organizations
To protect affected organizations, all victim identifiers have been redacted. Organization tokens ([ORG-n] and [EDU-n]) remain consistent throughout this report, allowing repeated organizations to be tracked across multiple entries.

Figure 3. Excerpt of compromised URLs in result2.txt
Government Sector
Analysis of gov.txt identified 30 government-related domains with successfully deployed webshells.
Malaysia accounted for the majority of compromised government domains, with 26 affected .gov.my domains. Additional victims included a U.S. state government environment, while the remaining entries consisted of commercial URLs and hosting services operated by private companies.
The identified government-related domains are summarized below.
| Domain | Country | Function |
|---|---|---|
forms.[ORG-1].gov | United States | Online forms service |
ev[REDACTED].[ORG-1].gov | United States | Event management system |
eams.[ORG-2].gov.my | Malaysia | Civil aviation asset administration system |
aset.[ORG-3].gov.my | Malaysia | Asset management system |
aset[REDACTED].[ORG-4].gov.my | Malaysia | Asset and warehouse management |
easet.[ORG-5].gov.my | Malaysia | Electronic asset management |
space.[ORG-6].gov.my | Malaysia | Internal operations system |
it[REDACTED].[ORG-6].gov.my | Malaysia | Transport management system |
ep[REDACTED].[ORG-6].gov.my | Malaysia | Electronic evaluation system |
my[REDACTED].[ORG-6].gov.my | Malaysia | Internal portal |
www5.[ORG-6].gov.my | Malaysia | Web server |
eli.[ORG-6].gov.my | Malaysia | E-learning system |
www4.[ORG-6].gov.my | Malaysia | Web server |
e-[REDACTED].[ORG-6].gov.my | Malaysia | Electronic recruitment system |
my[REDACTED].[ORG-6].gov.my | Malaysia | Internal operations portal |
sp[REDACTED].[ORG-6].gov.my | Malaysia | Internal administrative system |
svr-aset.[ORG-7].gov.my | Malaysia | Asset management server |
aset.[ORG-8].gov.my | Malaysia | Asset management system |
ad[REDACTED].[ORG-8].gov.my | Malaysia | Complaints and reporting system |
aset.[ORG-9].gov.my | Malaysia | Asset management system |
sp[REDACTED].[ORG-10].gov.my | Malaysia | Administrative and asset management system |
helpdesk.[ORG-11].gov.my | Malaysia | IT help desk |
spa.[ORG-12].gov.my | Malaysia | Human resources and recruitment system |
spa.[ORG-13].gov.my | Malaysia | Human resources and recruitment system |
sp[REDACTED].[ORG-14].gov.my | Malaysia | Administrative system |
sp[REDACTED].[ORG-15].gov.my | Malaysia | Administrative system |
sp[REDACTED].[ORG-16].gov.my | Malaysia | Administrative system |
spa.[ORG-17].gov.my | Malaysia | Human resources and recruitment system |
[ORG-18].net | Other | General website |
sdd[REDACTED].[ORG-19].com | Other | Web application and hosting service |

Figure 4. Government-related victims in gov.txt
Education Sector
Analysis of edu.txt identified 15 education-related domains with successfully deployed webshells.
Most education-sector victims were located in the United States, accounting for 14 of the 15 identified domains.
The compromised systems primarily included university URLs, admissions portals, student and staff portals, and internal administrative services. One additional victim was a global education-focused SaaS platform.
The identified education-related domains are summarized below.
| Domain | Country | Function |
|---|---|---|
[EDU-1].edu | United States | University main website |
www.[EDU-1].edu | United States | University main website |
www2.[EDU-1].edu | United States | Legacy web server |
my.[EDU-2].edu | United States | Student and staff portal |
[EDU-3].edu | United States | University main website |
www.[EDU-3].edu | United States | University main website |
apply.[EDU-3].edu | United States | Admissions system |
[EDU-4].edu | United States | University main website |
www.[EDU-4].edu | United States | University main website |
intranet.[EDU-4].edu | United States | Staff intranet |
bo[REDACTED].[EDU-5].edu | United States | Development environment |
fro[REDACTED].[EDU-6].edu | United States | Login and portal system |
ss[REDACTED].human.[EDU-7].edu | United States | Internal service |
admin.[EDU-8].com | United States | Administrative system |
edu.[EDU-9].com | Global | ERP, HR, and education management SaaS |

Figure 5. Education-related victims in edu.txt
Accessible Webshell Examples
Analysis of the URLs listed in result2.txt identified 398 URLs that remained accessible at the time of analysis.
These URLs returned responses consistent with the recorded webshell locations, indicating that the corresponding webshell files were still present on the affected servers rather than merely having been recorded as uploaded.
Government
- Target:
aset.[ORG-9].gov.my - Country: Malaysia
- System: Government asset management system
Figure 6. Recorded webshell page still reachable — Malaysian government asset management system (interface loaded)
Education
- Target:
ss[REDACTED].human.[EDU-7].edu - Country: United States
- System: University human resources / internal service
Figure 7. Recorded webshell page still reachable — university internal service (interface loaded)
Nonprofit
- Target:
to[REDACTED].fi - Country: Finland
- System: Nonprofit foundation
Figure 8. Recorded webshell page still reachable — Finnish nonprofit foundation (interface loaded)
Conclusion
Analysis of the attacker infrastructure identified a large-scale campaign exploiting the Adobe ColdFusion vulnerability CVE-2023-26360 to deploy command-execution webshells across internet-facing servers.
Collected artifacts confirmed the successful deployment of webshells to 4,244 URLs spanning government, higher education, nonprofit, and commercial organizations across multiple countries. Verification showed that 398 of these webshells remained accessible during analysis, indicating that some affected organizations may still be exposed to arbitrary command execution.
Because webshells can remain on compromised systems after the underlying vulnerability has been patched, organizations should assume potential compromise and conduct a comprehensive incident response investigation rather than relying solely on vulnerability remediation.
Minor language artifacts in the tooling — such as a Simplified Chinese comment in exp.py — are consistent with a Simplified Chinese-speaking operator, but this is a weak signal and is insufficient to attribute the activity to any specific individual, group, or state.