Netskope Threat Labs

SpringShell

ATP Sandbox Adv. HeuristicsAV

SpringShell (a.k.a. Spring4Shell) is a remote code execution vulnerability in the Spring Framework that allows cyberattackers to execute arbitrary code on affected Java applications. Crafted requests to applications running on vulnerable configurations could modify class properties and achieve code execution, and exploits circulated within hours of disclosure. Cyberattackers used the flaw to deploy web shells and cryptominers on internet facing servers, and patching and configuration hardening remain essential.

First seen
April 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.SpringShell.A.FFFFFFFE
Dump:Generic.SpringShell.A.FFFFFFFE
Exploit.SpringShell.A
Exploit.SpringShell.B
Exploit.SpringShell.D
Generic.SpringShell.A.00694CC0
Generic.SpringShell.A.026E2C12
Generic.SpringShell.A.03AD03B3
Generic.SpringShell.A.045FE8BB
Generic.SpringShell.A.0538613F