logo

BlueShell Used in Attacks Against Linux Systems in Korea (2)

ID: 40adedb3-5c75-5104-a1e5-cf80c7c5bb05

STIX ID: report--40adedb3-5c75-5104-a1e5-cf80c7c5bb05

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-02-08

Date Updated: 2026-04-26

Author: Sanseo

...
...

AhnLab ASEC details BlueShell, a Go-written backdoor actively used in targeted attacks on Linux systems (primarily Korea and Thailand). The report covers customized variants that load configuration from environment variables, memory-only execution via an XOR-encrypted dropper, a parent dropper disguised as the Linux `id` command to maintain persistence, TLS-protected C2 communications, and provides confirmed samples, MD5 hashes, and C2 URLs/hosts as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.