Tiny SHell is a lightweight, open-source remote-access backdoor for Unix-like systems, with documented Linux and macOS implementations, including a SPARC variant. Its core functionality comprises interactive shell access, file upload, and file download, enabling remote command execution and bidirectional file transfer. It uses HMAC-SHA1-based key derivation and AES-128 encryption to protect command-and-control communications. Its publicly available source code has also served as the basis for other backdoors, notably Rekoobe.
Tiny SHell has been deployed in targeted attacks against Mac users and in TeamTNT campaigns against Linux servers and cloud infrastructure. TeamTNT downloaded it alongside other tools during SSH-based propagation. In targeted macOS intrusions, attackers installed a modified variant over SSH using compromised credentials. That variant, known as TinyTim, retained Tiny SHell's core functionality while adding XOR-obfuscated strings, an external INI-style configuration file, encoded command-and-control settings, code signing, and ptrace-based anti-debugging checks. These modifications primarily improve stealth and configurability rather than expand the core command set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to spreading to other machines the following files are downloaded: docker-update (XMRig) tshd (Tiny SHell) kube (Tsunami) bioset (Rathole).
7 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor functionality incorporated into the analyzed BPFDoor data-plane variants to provide interactive shells and file uploads and downloads. The BPF Rekoobe sample also uses the standard Tiny Shell/Rekoobe cryptography and command interface.
Linux/UNIX backdoor; content describes YARA detections for ELF variants (including SPARC) using byte patterns, XOR sequences, and syscall-name artifacts.
A small Unix backdoor mentioned as one of the tools downloaded by TeamTNT during lateral movement and post-compromise activity.
Open-source backdoor program whose source code served as the basis for Rekoobe. It supports encrypted C2 communications and both reverse-shell and bind-shell style operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.