Netskope Threat Labs

Weevely

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Weevely is an open source web shell generator and terminal that provides stealthy remote control of a compromised web server over HTTP. Penetration testers use it in authorized assessments, and cyberattackers use it to operate backdoors planted on servers they have compromised.

First seen
January 2023
Last seen
October 2026
WeevelyShell
Alert Name
Generic.Linux.Weevely.A.6D1AFF1C
Generic.Linux.Weevely.A.76FD02F6
Generic.Linux.Weevely.A.C0E6D50C
Generic.Linux.Weevely.A.CF17E331
Script-PHP.Backdoor.WeevelyShell
Script-Python.Hacktool.WeevelyShell
Trojan.PHP.Weevely.1
Win32.Backdoor.WeevelyShell