logo

New Malware Framework Enables Screen Control and UAC Bypass

ID: 497c660e-17a4-5ea2-9e1a-e1c176dd3310

STIX ID: report--497c660e-17a4-5ea2-9e1a-e1c176dd3310

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Mayura Kathir

...
...

A security vendor (Cato CTRL) detected and blocked a targeted intrusion against a global manufacturing organization that used a custom implant called TencShell—derived from the open-source Rshell framework—delivered via a staged, in-memory Donut shellcode payload disguised as a .woff font; the implant supports screen control, browser artifact access, UAC bypass, SOCKS5 pivoting, and persistence, and the report includes numerous indicators of compromise and suspected (but inconclusive) China-linked attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.