New Malware Framework Enables Screen Control and UAC Bypass
ID: 497c660e-17a4-5ea2-9e1a-e1c176dd3310
STIX ID: report--497c660e-17a4-5ea2-9e1a-e1c176dd3310
Feed Name: GBHackers
A security vendor (Cato CTRL) detected and blocked a targeted intrusion against a global manufacturing organization that used a custom implant called TencShell—derived from the open-source Rshell framework—delivered via a staged, in-memory Donut shellcode payload disguised as a .woff font; the implant supports screen control, browser artifact access, UAC bypass, SOCKS5 pivoting, and persistence, and the report includes numerous indicators of compromise and suspected (but inconclusive) China-linked attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
