China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer
ID: 13e846cf-3ac6-54f7-bdf0-99a11755e372
STIX ID: report--13e846cf-3ac6-54f7-bdf0-99a11755e372
Feed Name: Infosecurity Magazine (News)
**Executive summary:** Cato Networks’ researchers blocked an intrusion targeting an Indian site of a global manufacturer and analyzed an undocumented Go-based implant named TencShell, a customized variant of the Rshell C2 framework. The operation used a first-stage dropper, Donut shellcode, a masqueraded .woff web-font, in-memory payload execution and web-like C2 traffic spoofing Tencent-style API paths; investigators suspect a China-linked actor but say attribution is not definitive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
