logo

Taking SHELLTER: a commercial evasion framework abused in-the-wild

ID: 8e7f57df-f82c-5daa-8647-ea6ba093ed10

STIX ID: report--8e7f57df-f82c-5daa-8647-ea6ba093ed10

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-04-27

...
...

Elastic Security Labs reports that the commercial AV/EDR evasion framework SHELLTER (likely Elite v11.0) has been acquired and abused since April 2025 to package and deploy multiple infostealer campaigns (LUMMA, RHADAMANTHYS, ARECHCLIENT2). The report provides in-depth technical analysis of SHELLTER’s evasion capabilities (polymorphic shellcode, unhooking via file-mapping, indirect syscalls, AMSI bypass, VEH API proxy, AES-128-CBC + LZNT1 payload protection), embedded license-based kill-switches, YARA detection rules, IOCs (SHA256s, IPs, domain) and a dynamic unpacker to extract payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.