logo

New “TencShell” Malware Weaponizes Open-Source Rshell via Third-Party Access

ID: 0d214afb-cb8d-5575-8066-b51d2387240c

STIX ID: report--0d214afb-cb8d-5575-8066-b51d2387240c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

Cato CTRL intercepted a targeted intrusion that weaponized the open-source Rshell framework into a Go-based implant named TencShell delivered via a Donut dropper hidden as a .woff font; the malware enabled in-memory execution, web-like C2, credential theft and lateral pivoting through third-party access, with suspected (but unconfirmed) China-linked attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.