Netskope Threat Labs

Godzilla

ATP Sandbox Adv. Heuristics

Godzilla is a web shell family that runs on PHP and Java application servers and gives operators encrypted remote control through the HTTP protocol of the compromised site. Cyberattackers commonly plant it on internet facing servers after exploiting content management systems, and its encrypted session format helps it evade web traffic inspection.

First seen
July 2024
Last seen
October 2026
Alert Name
ByteCode-JAVA.Backdoor.Godzilla