Horse Shell is a custom firmware implant for TP-Link routers associated with the China-aligned espionage cluster Camaro Dragon, which has overlap with Mustang Panda activity. It is designed to be embedded into router firmware to provide persistent remote access and to turn compromised network devices into anonymous operational infrastructure for the threat actor. The implant has been described as a C++ malware component tailored for TP-Link routers and linked to a Bring Your Own Firmware tradecraft model that enables compromise of devices through malicious firmware images, including systems with read-only file system constraints. Horse Shell has been noted to share design similarities with APT31’s Pakdoor, although no code overlap has been established.
Its primary role is to maintain long-term access on compromised routers and support covert post-compromise operations. By residing in firmware, Horse Shell enables persistence at the network-device layer and can help operators conceal downstream activity behind hijacked edge infrastructure. This makes it useful both for sustaining access and for building relay or proxy-like infrastructure in support of broader espionage campaigns.
Horse Shell has been publicly linked to campaigns attributed to Camaro Dragon, a threat cluster involved in cyberespionage operations aligned with Chinese strategic interests. Reporting connecting Horse Shell to that cluster places it in the context of operations targeting foreign affairs and government-related entities, particularly those connected to Southeast and East Asia. The malware is therefore best understood as part of a broader state-aligned intrusion ecosystem that combines endpoint malware, tailored lures, and compromised network infrastructure to support intelligence collection and operational anonymity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related Camaro Dragon Hacker Group Attack TP-Link Routers to Deploy Remote Shells ... the Chinese state-sponsored group “Camaro Dragon” employs a custom “Horse Shell” malware embedded in TP-Link routers’ firmware
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom router firmware malware referenced only in related-content material about Camaro Dragon targeting TP-Link routers.
Horse Shell is a C++ firmware implant/backdoor for TP-Link routers, enabling persistent access and use as proxy/C2 infrastructure.
Custom router implant embedded in malicious TP-Link firmware to maintain persistent access and to build/operate anonymous infrastructure via compromised routers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.