The Shelby Strategy
ID: acd86713-d63a-5df0-8bb2-d0d3e1f17047
STIX ID: report--acd86713-d63a-5df0-8bb2-d0d3e1f17047
Feed Name: Elastic Security Labs
Elastic Security Labs analyzed a targeted phishing campaign (REF8685) delivering the SHELBY malware family that uses GitHub (and a DNS variant) for command-and-control and AES-based payload decryption; the loader performs extensive sandbox checks, establishes persistence, and reflectively loads a low-detection backdoor that can exfiltrate data and execute operator commands. The report includes IOCs (file hashes, domains, IPs), YARA rules, and notes operational risks such as embedded GitHub PATs that could allow third parties to hijack infected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
