RShell is a cross-platform backdoor associated with China-linked intrusion activity and also exists as an open-source offensive security framework from which later implants such as TencShell were derived. In observed malicious operations, RShell was used by the APT27 cluster, including aliases such as Iron Tiger and LuckyMouse, in a supply-chain compromise of the MiMi chat application. Trojanized MiMi builds delivered RShell to macOS users, and related Linux samples were also identified, indicating a multi-platform espionage-oriented deployment.
On compromised hosts, RShell establishes command-and-control communications over TCP using Binary JSON messages. Documented variants send host profiling data at startup, including system and user context, and maintain periodic keepalive traffic. Supported operator functions include remote shell command execution and file-management operations such as directory listing, file upload, download, read, write, and deletion. Linux-focused reporting also describes variants that collect host and process metadata, support encrypted command-and-control data exchange, and in some cases use DNS-based communications. Some Linux samples implement persistence through systemd service creation when running with sufficient privileges.
RShell has been observed primarily in targeted surveillance and cyber-espionage contexts rather than broad criminal distribution. Delivery has been tied with high confidence to trojanized software in the MiMi supply-chain compromise. The malware targets non-Windows systems, especially macOS and Linux, and reflects sustained operator interest in cross-platform access within strategic intrusion campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mimi is a Chinese-speaking Electron App... trojanized since May 26, 2022 to download and execute a Mach-O binary dubbed “rshell”.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
0x0B EXECUTE_COMMAND Execute system command... 0x17 INTERACTIVE_SHELL Launch shell session
The group “cmd” contains three commands: init(): start a bash data(data): write data to the bash close(): ends up the bash.
The retrieved payload is written in the temp folder, chmoded with execution permission and then, executed
In some cases the attackers modified a clean installer in about 90 minutes, inserting obfuscated JavaScript into electron-main.js.
This “Hello message” to the C2 server contains: ... the IPv4 adresses
This “Hello message” to the C2 server contains: ... the current username
MITRE ATT&CK® Tactic Technique ID ... System Network Connections Discovery T1049
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rshell is an open-source cross-platform offensive security framework that was repurposed and customized by the threat actor as the basis for TencShell.
An open-source Go-based cross-platform command-and-control framework that includes remote command execution, file and process management, terminal access, in-memory payload execution, and multiple C2 transports. In this report it is described as the basis from which TencShell was customized.
Cross-platform backdoor seen in trojanized MiMi chat installers; collects OS details, communicates over BSON/TCP, and supports interactive command execution and file operations.
Malware family previously observed on Linux and macOS, cited as evidence the actor targets non-Windows platforms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.