New “TencShell” Malware Weaponizes Open-Source Rshell via Third-Party Access
ID: 0d214afb-cb8d-5575-8066-b51d2387240c
STIX ID: report--0d214afb-cb8d-5575-8066-b51d2387240c
Feed Name: securityonline.info
Threat Score
Cato CTRL intercepted a targeted intrusion that weaponized the open-source Rshell framework into a Go-based implant named TencShell delivered via a Donut dropper hidden as a .woff font; the malware enabled in-memory execution, web-like C2, credential theft and lateral pivoting through third-party access, with suspected (but unconfirmed) China-linked attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
