logo

China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer

ID: 13e846cf-3ac6-54f7-bdf0-99a11755e372

STIX ID: report--13e846cf-3ac6-54f7-bdf0-99a11755e372

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

**Executive summary:** Cato Networks’ researchers blocked an intrusion targeting an Indian site of a global manufacturer and analyzed an undocumented Go-based implant named TencShell, a customized variant of the Rshell C2 framework. The operation used a first-stage dropper, Donut shellcode, a masqueraded .woff web-font, in-memory payload execution and web-like C2 traffic spoofing Tencent-style API paths; investigators suspect a China-linked actor but say attribution is not definitive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.