Executive Summary
SEASHARPEE is a web‑shell malware deployed by OilRig (APT34) to provide persistent remote access on compromised Windows servers. It facilitates command execution, file manipulation, and data exfiltration over HTTP, enabling covert operations within target networks.
Enhanced Description
SEASHARPEE is a web‑shell-based malicious component that has been publicly linked to the APT34 threat actor, commonly referred to as OilRig. The malware functions as a backdoor hosted on compromised Windows web servers, allowing adversaries to upload and execute arbitrary code through HTTP requests. It typically embeds itself within legitimate CGI or ASP files to evade detection, and leverages server‑side scripting languages (such as PHP, ASP.NET, or JSP) to provide an interactive remote interface. Once installed, SEASHARPEE offers a full range of post‑compromise capabilities: it can read and write files, spawn system processes, and exfiltrate data through the same web channel. By issuing encoded payloads via HTTP parameters, attackers can run PowerShell or command‑line binaries with elevated privileges. The web shell also supports rudimentary persistence mechanisms, such as modifying web directory permissions or creating scheduled tasks on the victim machine. Its lightweight design facilitates stealthy operations and reduces the likelihood of triggering host‑based intrusion detection systems. The threat actor uses SEASHARPEE mainly to establish long‑term access within targeted infrastructures—often oil, gas, and petrochemical enterprises—to gather intelligence, exfiltrate intellectual property, or conduct lateral movements across internal networks. By exploiting web servers that are already exposed to the internet, OilRig can bypass perimeter defenses and maintain covert command and control channels. Overall, SEASHARPEE exemplifies the industry shift toward server‑side shells as a preferred C2 vector for APT actors seeking persistence, data theft, and covert operations.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core facts (web‑shell nature, association with OilRig) is moderate due to cited sources. However, detailed behavior—payload handling, persistence strategies—and exact deployment paths are not fully validated, creating analytical gaps.
SEASHARPEE is a Web shell that has been used by OilRig. (Citation: FireEye APT34 Webinar Dec 2017)