Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RuntimeBrokerApi.dll was decrypted only for selected hosts and loaded directly into memory, after which the second-stage backdoor used myCode to retrieve tasking and return data.
RuntimeBrokerApi.dll was decrypted only for selected hosts and loaded directly into memory, after which the second-stage backdoor used myCode to retrieve tasking and return data. | The HTTPService.dll and HTTPApi.dll samples documented by Elastic Security Labs as SHELBYLOADER and SHELBYC2 ... are classified as HOTAIR and AEROSTAT and associated with UNC5795.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Both the loader and backdoor are obfuscated with the open-source tool Obfuscar, which employs string encryption as one of its features.
The malware generates an AES key and initialization vector (IV) from the contents of License.txt... It proceeds to decrypt the file HTTPApi.dll, which contains the backdoor payload.
It crafts HTTP requests to interact with GitHub... The request is sent to the GitHub API endpoint... https://api.github.com/repos/<owner>/<repo>/contents/<unique identifier>/<file>.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Selectively activated .NET backdoor that uses a separate GitHub repository for command retrieval and result exchange, with a Cloudflare Worker fallback relay. It supports in-process PowerShell execution, file upload and download, ZIP extraction, and API-limit queries. Commands and results are Base64-encoded. Repository tasking exposed two activated victims, with confirmed credential theft and at least 1 GB of data exfiltrated from a government cloud environment. The report attributes the examined activity to UNC5795 with medium-to-high confidence.
ShelbyC2 is a Windows Trojan with command and control (C2) capabilities, detected via specific string and byte patterns on x86 systems.
A .NET backdoor implant providing remote command execution through GitHub-based C2. It uses a host-derived identifier and mutex, sends heartbeat timestamps, receives per-victim or broadcast commands, uploads and downloads files, can decrypt and reflectively load additional .NET payloads, and executes arbitrary PowerShell commands. Its embedded GitHub PAT can enable third parties with the token to access victim data or hijack active infections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.