TinyShell is an open-source Unix backdoor used to establish remote command-and-control access and persistent footholds on compromised systems. It has been deployed in active and passive configurations, including reverse-shell and bind-shell modes. Multiple customized TinyShell variants have been observed using distinct command-and-control methods to reduce detection opportunities.
TinyShell has been used by several threat clusters in intrusions affecting Linux systems and network appliances. UNC2891, also associated with LightBasin activity, used it for persistent access in banking and ATM-network compromises, including operations involving internal footholds obtained through physically implanted network hardware. UNC3886 deployed customized TinyShell-based backdoors on end-of-life Juniper Junos OS routers, alongside logging-disabling and process-injection tradecraft, to maintain long-term espionage access. UNC4540 used a TinyShell variant within a persistence-focused malware suite targeting SonicWall Secure Mobile Access appliances. Red Menshen has also used TinyShell as a passive persistence mechanism on staging systems during lateral movement in telecommunications environments.
Observed deployments emphasize covert, durable remote access across Unix-like infrastructure, including Linux hosts, Junos-based routers, and security appliances. In some operations, TinyShell communications used outbound channels that bypassed conventional perimeter controls, including mobile-data connectivity and dynamic DNS-based infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Juniper vydala bezpečnostné aktualizácie pre svoj sieťový operačný systém Junos OS, ktoré opravujú aktívne zneužívanú zraniteľnosť. CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom. | Zariadenia sú infikované až 6 variantmi open-source backdooru TinyShell. Každý variant na maskovanie svojej činnosti používa iné C2 a inú metódu riadiacej komunikácie.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools linked to the actor in previous attacks include Slapstick, Tinyshell, Steelhound, Steelcorgi, Wingjook, Wingcrack, Binbash, Wiperight, and the Mignogcleaner, all of which Mandiant confirmed as still deployed in LightBasin attacks.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
Common Patterns Across Intrusions Analysis of both intrusion sets, along with additional intelligence from other affected operators in this campaign, identified the following consistent patterns: TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
The malware used on SonicWall devices consists of an ELF binary, the TinyShell backdoor, and several bash scripts that show a deep understanding of the targeted network devices.
Also dropped are Sliver, TinyShell (a Unix backdoor), keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
A suspected Chinese hacking campaign has been targeting unpatched SonicWall Secure Mobile Access (SMA) appliances... While it is unclear what vulnerability was used to compromise devices, Mandiant says that the targeted devices were unpatched, making them likely vulnerable to older flaws.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
TinyShell and China Chopper were both used to establish persistence on staging systems during lateral movement.
"In March 2025, it was revealed that Chinese cyber-espionage actors were deploying custom backdoors on EoL Junos OS MX routers to drop a set of ‘TinyShell’ backdoor variants."
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
CVE-2025-21590 by lokálny útočník s prístupom k shell-u mohol zneužiť na obídenie bezpečnostného mechanizmu Veriexec, vykonanie škodlivého kódu a získanie úplnej kontroly nad systémom.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
Mandiant has documented the activities of a team it's called UNC2891 and its targeting of Solaris systems with backdoors dubbed TINYSHELL and SLAPSTICK and a rootkit called CAKETAP.
the backdoor process, which was named “lightdm” in an attempt to masquerade as the legitimate LightDM display manger, but was found at an unusual location
Backdoor named lightdm with legitimate-looking arguments, run from /tmp and /var/snap/.snapd.
Nesprávne overovanie pôvodu súborov a nedostatočnú izoláciu procesov možno injekciou kódu do legitímnych procesov zneužiť na obídenie zabudovaného bezpečnostného mechanizmu Veriexec.
These backdoors included active and passive functions, and embedded scripts that disabled logging mechanisms on the device.
Also dropped are Sliver, TinyShell, keyloggers, and brute-force utilities to facilitate credential harvesting and lateral movement.
The broadly-connected network monitoring server was used as a pivot; a secondary backdoor on the internet-facing mail server maintained access.
where the BPFdoor controller was deployed... The BPFdoor backdoor was deployed on these systems for long-term persistence.
Additionally, firewalld launches other malware components, like TinyShell, to establish a reverse shell on the appliance for easy remote access.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TINYSHELL component was listed among Fire Ant intrusion artifacts.
A backdoor used by UNC2891 for outbound command-and-control over 4G/mobile data, providing persistent remote access from the implanted Raspberry Pi and related footholds.
A custom backdoor family used by UNC3886 on Junos OS routers, including active and passive backdoor functions and embedded scripts that disabled logging mechanisms on the device to support stealth and persistence.
A backdoor used to establish persistence on staging systems during lateral movement as part of the broader telecom intrusion campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.