hackshell is a lightweight Linux post-exploitation utility that has been repurposed in the ShadowHS intrusion framework into an interactive, operator-driven backdoor and post-compromise platform. The weaponized variant is deployed by an obfuscated multi-stage shell loader that reconstructs an encrypted payload and executes it from anonymous memory-backed file descriptors, avoiding persistent payload files. It also spoofs process arguments to reduce attribution and forensic visibility.
The ShadowHS variant performs host, user, terminal, privilege-boundary, kernel, and security-tool discovery, including checks for endpoint defenses, kernel protections, loaded modules, and memory-backed or deleted executables. Its on-demand functionality includes extraction of credentials and secrets from live process memory and filesystem artifacts, SSH endpoint discovery and credential brute forcing for lateral movement, privilege-escalation support, and cryptomining workflows. It supports covert operator-directed staging and exfiltration through user-space tunneling and includes logic to identify and terminate competing miners and other implants. The observed deployment and functionality target Linux servers, particularly environments with enterprise defensive tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool cited as implementing a similar interpreter-led in-memory execution technique through its _memexec() function.
An open-source post-exploitation tool that, in this campaign, is heavily modified/weaponized and used as the in-memory payload to provide an interactive operator-controlled post-exploitation environment with modules for credential theft, lateral movement, and privilege escalation.
Referenced as the base utility that was weaponized/extended to form ShadowHS’s post-compromise platform capabilities.
An open-source/lightweight post-exploitation helper that, in this activity, is heavily modified and weaponized into an in-memory operator framework providing interactive access plus modular capabilities (reconnaissance, defense discovery, credential access, lateral movement, exfiltration, and optional cryptomining).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.