FruitShell is a publicly available PowerShell reverse shell observed in operations. It establishes command-and-control access from a compromised host and enables an operator to execute arbitrary commands remotely. The code contains hard-coded natural-language prompts intended to bypass or influence LLM-powered security detection and analysis systems. No specific delivery vector, threat-actor attribution, or targeted sector is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
There were no new MITRE attack techniques. Seven of eight operations ran T1059, Command & Scripting Interpreter, the single most ordinary technique in the framework.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell reverse shell that embeds prompts intended to bypass LLM-based security analysis.
Reverse shell malware engineered to evade or bypass AI-assisted security controls/detections.
Named as an example of 'AI-enabled malware' observed/covered by Google GTIG; specific functionality not described in the provided content.
PowerShell reverse shell script with LLM-aware prompt instructions, designed to bypass LLM-based analysis; primarily a penetration testing tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.