Skip to main content
Mallory
MalwareUsed by 1 actor

SEASHARPEE

SEASHARPEE is a web shell. Reported capabilities include executing commands on victim systems and timestomping files on compromised hosts. Mandiant reported that UNC215 deployed the SEASHARPEE web shell in April 2019 against financial and high-tech organizations in the Middle East and Asia. The same reporting states UNC215 used SEASHARPEE after the web shell’s code was leaked in March 2019 via the Telegram channel Lab Dookhtegan, and describes it as an Iranian-associated web shell. High-confidence context directly links SEASHARPEE to UNC215 post-compromise activity and use on victim web infrastructure for command execution and anti-forensics via timestamp manipulation.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
unc215

In April 2019, UNC215 deployed the SEASHARPEE web shell against financial and high-tech organizations in the Middle East and Asia.

via fireeyefireeye.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.003Windows Command ShellEvidence3
TacticExecution

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

Persistence

1 technique
T1505.003Web ShellEvidence2

"CVE-2019-0604 was used to deliver web shells"; "pivoted to multiple OWA servers and installed web shells"

Stealth

1 technique
T1070.006TimestompEvidence2
TacticStealth

APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1071.001Web ProtocolsEvidence1

MITRE ATT&CK Techniques list includes "T1071.001 ... Web Protocols"; web shells and C2 over common protocols are implied.

T1105Ingress Tool TransferEvidence1
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.