logo

Invisible Intruder: “ShadowHS” Malware Weaponizes Hackshell on Linux

ID: e38b24a5-ee51-5226-a297-2a602827134b

STIX ID: report--e38b24a5-ee51-5226-a297-2a602827134b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Cyble Research & Intelligence Labs uncovered ShadowHS, a sophisticated fileless Linux intrusion campaign that uses a multi-stage in-memory loader to deploy a weaponized version of hackshell for interactive, operator-driven post-exploitation. The framework evades detection through process name spoofing and anonymous file descriptors, fingerprints and disables EDR/competing malware, supports credential theft, SSH lateral movement and privilege escalation, and exfiltrates data covertly via user-space tunneling (GSocket).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.