“Put simply - we have been hijacking backdoors (that were reliant on now abandoned infrastructure and/or expired domains) that themselves existed inside backdoors, and have since been watching the results flood in.”

Attackers who drop web shells are dropping someone else’s backdoor too. watchTowr bought lapsed domains the shells phone home to and found 4,000 live backdoors. One victim is the Federal High Court of Nigeria. Anyone with $20 could have done the same.