logo

Cyble Research Discovers ShadowHS, an In-Memory Linux Framework for Long-Term Access

ID: 64695102-2a99-5f85-b61e-60b4ab8ea249

STIX ID: report--64695102-2a99-5f85-b61e-60b4ab8ea249

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-01-30

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

Cyble Research & Intelligence Labs (CRIL) uncovered ShadowHS, a stealthy, fileless Linux post-exploitation framework that reconstructs and executes a weaponized hackshell in memory using an encrypted loader; it emphasizes operator-controlled reconnaissance, credential theft, lateral movement, privilege escalation, covert exfiltration over GSocket/DBus, cryptomining modules, and EDR/AV fingerprinting and anti-competition logic to maintain long-term, stealthy access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.