- [2026.06.24]0byt3m1n1-V2
File manager webshell v2.2 with zero authentication and a runtime supply-chain dropper. Indonesian scene (zerobyte-id). No password, no session, no token — every function is open to any visitor. On every page load, fetches its own source from a hardcoded GitHub URL and writes it to the webroot.
- [2026.06.24]Alfa Shell V4 "Tesla"
The most deployed variant of the Alfa webshell family. Full-featured control panel with file manager, database browser, and CGI backdoor installer — and a hidden mail() beacon that reports every compromised host back to the kit author.
- [2026.06.24]Alfa3
The kit's 'alfa3.php' is not a separate, older 'alfa3' family — it is an Alfa Shell V4 'Tesla' build, with the Hmei7 mail() surveillance beacon and create_function obfuscation. It is a distinct file from alfav4-tesla.php (different hash and size), not a byte-identical copy.
- [2026.06.24]b374k
Gold standard compact webshell with anti-bot 404 evasion. Returns a fake 404 page to automated scanners while serving the real shell to interactive browsers. W0rm supply-chain infected in redistributed copies.
- [2026.06.24]c99
The original webshell — attributed to locus7s / Locus7 group. Ships with zero authentication by default and a cookie-driven PHP object injection that gives any visitor full control. The ancestor of the modern PHP shell ecosystem.
- [2026.06.24]IndoXploit
Indonesian-scene webshell with 10 outbound TLS-disabled connections, a W0rm supply-chain backdoor that fires on every unauthenticated visit, and trivially crackable MD5 auth. Every deployment is MITM-able and pre-auth exploitable simultaneously.
- [2026.06.24]m4r5-sh3ll
Indonesian-scene webshell with modern Bootstrap 4 dark UI, community-public default credentials, and eval(base64_decode()) obfuscated core. Built for the bigsecc hacker community — the most user-friendly shell in Tier 1.
- [2026.06.24]Ninja
Full-featured webshell with embedded PHPMailer, a redistributor-injected JavaScript tracking beacon, and a hardcoded plaintext password. Turns every compromised server into a phishing platform while reporting the operator's activity to a third-party ad network.
- [2026.06.24]r57
Classic Russian webshell and one of the earliest full-featured PHP shells to circulate widely. Carries a W0rm supply-chain backdoor and a pre-auth local file inclusion on the very first line of source — the operator's tool is compromised before it even loads.
- [2026.06.24]Stupidc0de Backdoor
The flagship Tier-2 card. 90 KB / 2030 lines — the largest tool in the corpus. Indonesian scene (Stupidc0de Family: Putra-Attacker, Daryun, Shor7cut, Osvaldas, Sinkaroid). Zero authentication on 12+ function modules. Pre-auth RCE, LFI, and arbitrary upload all confirmed live. Five runtime supply-chain remote-includes. WordPress admin reset module. zone-h mass-defacement notifier.
- [2026.06.24]whmcs-killer-v3
WHMCS-targeting webshell with six independent attack vectors — W0rm supply-chain RCE, trivial client-side session forgery, pre-auth file inclusion with eval, arbitrary file upload, SQL injection, and stored XSS. Every vector is pre-auth. Harvests the WHMCS billing database: client records, payment details, hosting credentials, domain registrations.
- [2026.06.24]WSO (Web Shell by Orb)
The workhorse of the Russian webshell scene — compact, battle-tested, zero authentication on default install, and carrying a W0rm supply-chain backdoor that gives a third party unauthenticated RCE on every host the operator compromises. Five independent attack surfaces. Highest severity in corpus.