logo

Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware

ID: c31c7172-768b-5d86-a7dd-7b304608d570

STIX ID: report--c31c7172-768b-5d86-a7dd-7b304608d570

Feed Name: Cato Networks

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-07-23

Author: Tal Biran

...
...

In April 2026 Cato CTRL detected and blocked an attempted intrusion against a global manufacturer's environment that deployed a customized Go-based implant called TencShell (derived from the Rshell framework). The report documents a staged infection chain—first-stage dropper, Donut shellcode delivered via a masqueraded .woff resource, reflective in-memory PE loading, and web-like Tencent-imitating C2—followed by analysis of capabilities (remote shell, in-memory execution, SOCKS5 proxying, screen control, persistence via Run key), extensive IOCs (IP, domain, hashes), and MITRE ATT&CK mappings; attribution is suspected China-linked but not conclusive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.