logo

MalKamak APT’s ShellClient RAT: Inside Operation GhostShell

ID: fee9e12c-af4b-5bb2-a92f-d7158edd4f30

STIX ID: report--fee9e12c-af4b-5bb2-a92f-d7158edd4f30

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2025-11-11

Date Updated: 2026-07-22

Author: Picus Labs

...
...

MalKamak (Operation GhostShell) is a targeted espionage group active since at least 2018 that deployed a modular ShellClient RAT against aerospace and telecommunications firms (primarily in the Middle East). The RAT uses AES-encrypted payloads, Dropbox-based C2 (Commands/Agents/Results folders), Windows service persistence (nhdService via InstallUtil.exe), credential dumping (lsa.exe producing debug.bin), process masquerading, and various remote administration tools (PAExec, csvde.exe) to collect and exfiltrate sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.