logo

Hackers 'Shellter' Various Stealers in Red-Team Tool to Evade Detection

ID: e9958eec-dc5a-583a-b3cb-e8d674da9ea2

STIX ID: report--e9958eec-dc5a-583a-b3cb-e8d674da9ea2

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-07-08

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers observed threat actors using an illicit copy of the Shellter Elite evasion framework to package and deliver multiple infostealers (Lumma, Rhadamanthys/Sectop RAT/Sectop) through phishing lures and hosted files (e.g., MediaFire). The report describes specific evasion features abused (polymorphic self-modifying shellcode, DLL preloading, API-hook bypassing, debugger detection), provides at least one C2 IP:port, and notes Elastic released a dynamic unpacker to aid defenders; the actors are financially motivated and campaigns are ongoing with potential for further spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.