SYMBOLCOMMON_NAMEaka. SYNONYMS
win.sharpyshell (Back to overview)

SharPyShell

aka: ASPSHELL

Actor(s): APT41


SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime.

SharPyShell supports only C# web applications that runs on .NET Framework >= 2.0
VB is not supported atm.

References
2025-07-19Eye SecurityEye Security
SharePoint 0-day uncovered (CVE-2025-53770)
SharPyShell
2020-09-18Trend MicroTrend Micro
U.S. Justice Department Charges APT41 Hackers over Global Cyberattacks
Cobalt Strike ColdLock SharPyShell
2019-03-12antonioCoco
SharPyShell
SharPyShell

There is no Yara-Signature yet.