TencShell Command-and-Control Infrastructure
TencShell is a known C2 infrastructure used by suspected China-linked threat actors. Hunt.io observed an open directory sharing identical HTTP header fingerprints…
TencShell is a known C2 infrastructure used by suspected China-linked threat actors. Hunt.io observed an open directory sharing identical HTTP header fingerprints…
TuxBot v3 Evolution is a modular IoT botnet framework with C-based bot agent, Go-based C2 server, custom exploit VM, and Docker test…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
MODBEACON is a Rust-based RAT using gRPC streaming for encrypted C2 communication. It is memory-resident, modular, and uses Xray/V2Ray transport layer. Capabilities…
The China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) called MODBEACON. Chinese cybersecurity company…
LONGLEASH is a full-fledged backdoor framework developed by Chinese APT UAT-7810 as a successor to ShortLeash. It includes an executor component that…
ShortLeash is a custom backdoor developed by Chinese APT UAT-7810 that can contact an external server, host a web server, and act…
Cavern (aka Cav3rn) is a modular command-and-control framework used by Iranian nation-state hackers, linked to Cavern Manticore. It supports various post-exploitation modules…
Cybersecurity researchers at LevelBlue have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is capable of targeting Windows, Linux,…
QuimaRAT is a Java-based remote access trojan (RAT) advertised under a malware-as-a-service (MaaS) model, capable of targeting Windows, Linux, and macOS. It…