Logo
/
Blog/Analysis of a Large-Scale Adobe ColdFusion Campaign Deploying Webshells to 4,244 URLs
July 16, 20269 min readCyber Threat Intelligence
Share:

Analysis of a Large-Scale Adobe ColdFusion Campaign Deploying Webshells to 4,244 URLs

By Threat Intelligence Unit

Overview

Oasis Security identified a large-scale campaign targeting internet-facing Adobe ColdFusion servers by exploiting CVE-2023-26360.

Analysis of collected attacker infrastructure revealed the complete attack workflow, including the exploitation script used to deploy command-execution webshells, records of 4,244 successfully compromised URLs, and categorized victim lists spanning government, higher education, nonprofit, and commercial organizations across multiple countries.

Of the recorded webshells, 398 remained accessible during analysis, indicating that some affected organizations may still be exposed.



Executive Summary

  • Analysis of attacker infrastructure identified a large-scale campaign exploiting the Adobe ColdFusion vulnerability CVE-2023-26360 to deploy command-execution webshells
  • Collected attacker files confirmed 4,244 successfully compromised URLs spanning government, higher education, nonprofit, and commercial organizations across multiple countries
  • Of the recorded webshells, 398 remained accessible during analysis, leaving some affected organizations exposed through the deployed command-execution webshells


Infrastructure Analysis

Server-side files were collected from infrastructure hosted at the following server:

  • IP Address: 47.237.103.207
  • Geolocation: Singapore
  • Hosting Provider: Alibaba Cloud

Analysis of the collected files revealed multiple artifacts associated with the attacker's operation, including:

  • The exploitation script used to deploy the webshells
  • A list of 4,244 compromised URLs
  • Separate files categorizing government and education victims

The collected files indicate that the operator maintained structured records of successfully compromised systems and organized high-value targets by sector.



Attack Analysis

The operator exploited an Adobe ColdFusion remote code execution vulnerability to upload command-execution webshells to a large number of internet-facing servers, successfully compromising 4,244 URLs.

The campaign leveraged CVE-2023-26360, an unauthenticated Adobe ColdFusion remote code execution vulnerability caused by deserialization of untrusted data. The vulnerability has been actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.

Exploitation Script

Analysis of the collected files identified a custom Python script named exp.py, which automated exploitation across numerous target URLs.

The script exploited a vulnerable ColdFusion server by uploading command-execution webshells using CVE-2023-26360. The webshell payload was stored within the script as a Base64-encoded string in the payloadEnd variable and decoded at runtime before being delivered to each target.

exp.py exploit script

Figure 1. exp.py exploit script with Base64 webshell payload

Webshell Analysis

Decoding the payloadEnd value revealed the ColdFusion webshell.

The webshell provides a simple command-execution interface consisting of two input fields:

  • c — Specifies the executable program
  • o — Specifies the command-line arguments passed to the program

When submitted, the webshell executes the supplied command through the ColdFusion cfexecute tag and returns the output directly within the web interface.

Successful exploitation results were automatically written to result2.txt, which records the full URL of each uploaded webshell.

The operator additionally categorized compromised URLs into separate files:

  • gov.txt — Government-related organizations
  • edu.txt — Education-related organizations

These files indicate that the operator separately tracked organizations considered to be of higher interest.

ColdFusion webshell source

Figure 2. Decoded ColdFusion webshell using cfexecute



Victim Analysis

Analysis of result2.txt identified 4,244 URLs where the webshell was successfully uploaded.

The collected data indicates that the operator maintained separate records for organizations considered to be of higher interest by categorizing compromised targets into two sector-specific files:

  • gov.txt — Government-related organizations
  • edu.txt — Education-related organizations

To protect affected organizations, all victim identifiers have been redacted. Organization tokens ([ORG-n] and [EDU-n]) remain consistent throughout this report, allowing repeated organizations to be tracked across multiple entries.

result2.txt compromised URLs

Figure 3. Excerpt of compromised URLs in result2.txt



Government Sector

Analysis of gov.txt identified 30 government-related domains with successfully deployed webshells.

Malaysia accounted for the majority of compromised government domains, with 26 affected .gov.my domains. Additional victims included a U.S. state government environment, while the remaining entries consisted of commercial URLs and hosting services operated by private companies.

The identified government-related domains are summarized below.

DomainCountryFunction
forms.[ORG-1].govUnited StatesOnline forms service
ev[REDACTED].[ORG-1].govUnited StatesEvent management system
eams.[ORG-2].gov.myMalaysiaCivil aviation asset administration system
aset.[ORG-3].gov.myMalaysiaAsset management system
aset[REDACTED].[ORG-4].gov.myMalaysiaAsset and warehouse management
easet.[ORG-5].gov.myMalaysiaElectronic asset management
space.[ORG-6].gov.myMalaysiaInternal operations system
it[REDACTED].[ORG-6].gov.myMalaysiaTransport management system
ep[REDACTED].[ORG-6].gov.myMalaysiaElectronic evaluation system
my[REDACTED].[ORG-6].gov.myMalaysiaInternal portal
www5.[ORG-6].gov.myMalaysiaWeb server
eli.[ORG-6].gov.myMalaysiaE-learning system
www4.[ORG-6].gov.myMalaysiaWeb server
e-[REDACTED].[ORG-6].gov.myMalaysiaElectronic recruitment system
my[REDACTED].[ORG-6].gov.myMalaysiaInternal operations portal
sp[REDACTED].[ORG-6].gov.myMalaysiaInternal administrative system
svr-aset.[ORG-7].gov.myMalaysiaAsset management server
aset.[ORG-8].gov.myMalaysiaAsset management system
ad[REDACTED].[ORG-8].gov.myMalaysiaComplaints and reporting system
aset.[ORG-9].gov.myMalaysiaAsset management system
sp[REDACTED].[ORG-10].gov.myMalaysiaAdministrative and asset management system
helpdesk.[ORG-11].gov.myMalaysiaIT help desk
spa.[ORG-12].gov.myMalaysiaHuman resources and recruitment system
spa.[ORG-13].gov.myMalaysiaHuman resources and recruitment system
sp[REDACTED].[ORG-14].gov.myMalaysiaAdministrative system
sp[REDACTED].[ORG-15].gov.myMalaysiaAdministrative system
sp[REDACTED].[ORG-16].gov.myMalaysiaAdministrative system
spa.[ORG-17].gov.myMalaysiaHuman resources and recruitment system
[ORG-18].netOtherGeneral website
sdd[REDACTED].[ORG-19].comOtherWeb application and hosting service
gov.txt victim list

Figure 4. Government-related victims in gov.txt



Education Sector

Analysis of edu.txt identified 15 education-related domains with successfully deployed webshells.

Most education-sector victims were located in the United States, accounting for 14 of the 15 identified domains.

The compromised systems primarily included university URLs, admissions portals, student and staff portals, and internal administrative services. One additional victim was a global education-focused SaaS platform.

The identified education-related domains are summarized below.

DomainCountryFunction
[EDU-1].eduUnited StatesUniversity main website
www.[EDU-1].eduUnited StatesUniversity main website
www2.[EDU-1].eduUnited StatesLegacy web server
my.[EDU-2].eduUnited StatesStudent and staff portal
[EDU-3].eduUnited StatesUniversity main website
www.[EDU-3].eduUnited StatesUniversity main website
apply.[EDU-3].eduUnited StatesAdmissions system
[EDU-4].eduUnited StatesUniversity main website
www.[EDU-4].eduUnited StatesUniversity main website
intranet.[EDU-4].eduUnited StatesStaff intranet
bo[REDACTED].[EDU-5].eduUnited StatesDevelopment environment
fro[REDACTED].[EDU-6].eduUnited StatesLogin and portal system
ss[REDACTED].human.[EDU-7].eduUnited StatesInternal service
admin.[EDU-8].comUnited StatesAdministrative system
edu.[EDU-9].comGlobalERP, HR, and education management SaaS
edu.txt victim list

Figure 5. Education-related victims in edu.txt



Accessible Webshell Examples

Analysis of the URLs listed in result2.txt identified 398 URLs that remained accessible at the time of analysis.

These URLs returned responses consistent with the recorded webshell locations, indicating that the corresponding webshell files were still present on the affected servers rather than merely having been recorded as uploaded.

Government

  • Target: aset.[ORG-9].gov.my
  • Country: Malaysia
  • System: Government asset management system
Government webshell

Figure 6. Recorded webshell page still reachable — Malaysian government asset management system (interface loaded)

Education

  • Target: ss[REDACTED].human.[EDU-7].edu
  • Country: United States
  • System: University human resources / internal service
Education webshell interface

Figure 7. Recorded webshell page still reachable — university internal service (interface loaded)

Nonprofit

  • Target: to[REDACTED].fi
  • Country: Finland
  • System: Nonprofit foundation
Nonprofit webshell

Figure 8. Recorded webshell page still reachable — Finnish nonprofit foundation (interface loaded)



Conclusion

Analysis of the attacker infrastructure identified a large-scale campaign exploiting the Adobe ColdFusion vulnerability CVE-2023-26360 to deploy command-execution webshells across internet-facing servers.

Collected artifacts confirmed the successful deployment of webshells to 4,244 URLs spanning government, higher education, nonprofit, and commercial organizations across multiple countries. Verification showed that 398 of these webshells remained accessible during analysis, indicating that some affected organizations may still be exposed to arbitrary command execution.

Because webshells can remain on compromised systems after the underlying vulnerability has been patched, organizations should assume potential compromise and conduct a comprehensive incident response investigation rather than relying solely on vulnerability remediation.

Minor language artifacts in the tooling — such as a Simplified Chinese comment in exp.py — are consistent with a Simplified Chinese-speaking operator, but this is a weak signal and is insufficient to attribute the activity to any specific individual, group, or state.