Hackers 'Shellter' Various Stealers in Red-Team Tool to Evade Detection
ID: e9958eec-dc5a-583a-b3cb-e8d674da9ea2
STIX ID: report--e9958eec-dc5a-583a-b3cb-e8d674da9ea2
Feed Name: Dark Reading
Date Published: 2025-07-08
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers observed threat actors using an illicit copy of the Shellter Elite evasion framework to package and deliver multiple infostealers (Lumma, Rhadamanthys/Sectop RAT/Sectop) through phishing lures and hosted files (e.g., MediaFire). The report describes specific evasion features abused (polymorphic self-modifying shellcode, DLL preloading, API-hook bypassing, debugger detection), provides at least one C2 IP:port, and notes Elastic released a dynamic unpacker to aid defenders; the actors are financially motivated and campaigns are ongoing with potential for further spread.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
