RESHELL (also styled ReShell or Reshell) is a previously undocumented, ConfuserEX-packed .NET backdoor used in cyberespionage intrusions. It supports host information collection, file deployment, command execution, and AES-encrypted command-and-control communications. It has been deployed on compromised Windows systems by Earth Krahang, a China-nexus espionage actor that has targeted government entities, particularly in Southeast Asia, through spear-phishing and exploitation of public-facing servers. A separate long-running intrusion cluster targeting a Southeast Asian government, assessed with moderate confidence as Alloy Taurus (GALLIUM), also used RESHELL alongside web shells and credential-access tooling. In that activity, attackers attempted to execute the backdoor after exploiting Microsoft Exchange Server vulnerabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as Oracle Web Applications Desktop Integrator CVE-2022-21587 (CVSS 9.8) ... to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang was observed exploiting public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The advisory identifies RESHELL C&C servers.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as ... OpenFire CVE-2023-32315 (CVSS 7.5) to install backdoors such as Cobalt Strike, RESHELL, and XDealer. | Earth Krahang was observed exploiting public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The advisory identifies RESHELL C&C servers.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Krahang was observed exploiting public-facing servers "to install backdoors such as Cobalt Strike, RESHELL, and XDealer." The advisory identifies RESHELL C&C servers.
Earth Krahang delivers backdoors to establish access to victim machines. Cobalt Strike and two custom backdoors, RESHELL and XDealer, were employed during the initial stage of attack.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Earth Krahang abuses the trust between governments to conduct their attacks. We found that the group frequently uses compromised government webservers to host their backdoors and send download links to other government entities via spear phishing emails.
Earth Krahang exploited Oracle Web Applications Desktop Integrator CVE-2022-21587 and OpenFire CVE-2023-32315.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A bespoke malware/backdoor used by Earth Krahang in espionage intrusions.
A simple .NET backdoor with capabilities to collect information, drop files, and execute system commands. Its binaries are packed with ConfuserEX and its C2 communication is encrypted with AES.
Previously unknown backdoor (per Unit 42) used for access/persistence in the described espionage cluster.
Previously undocumented .NET backdoor (windows.exe) configured with an embedded C2 IP to enable remote arbitrary command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.