SHELLTER is a dual-use commercial Windows AV/EDR-evasion framework developed for authorized red-team operations. Illicitly acquired Shellter Elite v11.0 instances were used in financially motivated campaigns from April 2025 to package and load payloads including LUMMA, RHADAMANTHYS, and ARECHCLIENT2/SECTOP RAT. Observed campaigns used phishing lures directed at content creators and links promoted through gaming-related YouTube content. SHELLTER-protected binaries embed self-modifying polymorphic shellcode in legitimate programs and encrypt compressed payloads with AES-128-CBC. The framework incorporates extensive defense-evasion functionality, including runtime API resolution, fresh ntdll mapping and indirect syscalls to bypass user-mode hooks, call-stack concealment, memory-permission changes, debugger and hypervisor checks, AMSI bypass methods, decoy-module unlinking from process loader structures, and vectored-exception-handler-based API proxying. Embedded license and self-disarm metadata in malicious samples indicated that multiple campaigns may have used a single illicit Shellter Elite license.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
RHADAMANTHYS infections begin with YouTube videos targeting game hacking and gaming mods, with video comments linking to malicious files hosted on MediaFire. | Campaigns targeting content creators used sponsorship-opportunity lures impersonating Udemy, Skillshare, Pinnacle Studio, and Duolingo; emails included download links to .rar archives containing promotional material and a SHELLTER-protected executable.
Memory scan evasion techniques include decoding and re-encoding instructions at runtime, removal of execute permissions on inactive memory pages, reducing footprint... and using Windows internals structures, such as the PEB, as temporary data holding spots.
SHELLTER-protected samples commonly employ self-modifying shellcode with polymorphic obfuscation... legitimate instructions and polymorphic code helps these files evade static detection and signatures.
Observed samples employ time-based seeding to obfuscate API addresses... uses a seeded-ROR13 hashing algorithm on API names to resolve the function addresses at runtime.
По данным исследования Elastic Security Labs, даже коммерческий фреймворк SHELLTER использует полиморфную обфускацию (Polymorphic Code, T1027.014, Defense Evasion) для изменения байтовой последовательности при каждой генерации.
A sample deploys a simple C++ loader client abusing BITS (Background Intelligent Transfer Service) for C2.
To bypass API hooking techniques from AV/EDR vendors, SHELLTER maps a fresh copy of ntdll.dll... There are two methods of AMSI bypassing... in-memory patching of AMSI functions... [or] overwrite[s] the Scan function pointer with the address of the ret gadget.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial AV/EDR evasion framework reportedly abused (via illicitly obtained copies) by multiple infostealer operations.
A commercial dual-use AV/EDR evasion framework and loader used to package and deliver payloads while bypassing analysis and detection. Observed capabilities include polymorphic junk code, unhooking of ntdll, AES-128-CBC payload encryption, DLL preloading, API hashing, indirect syscalls, AMSI bypass, debugger and VM detection, memory scan evasion, and VEH-based API proxying.
A commercial dual-use AV/EDR-evasion framework maliciously used as a highly evasive loader. It embeds and decrypts payloads, uses polymorphic junk code, indirect syscalls, API/call-stack obfuscation, ntdll unhooking, AMSI bypasses, sandbox/debugger checks, memory-scan evasion, and vectored-exception-handler API proxying.
A commercial evasion framework reported as illicitly acquired and abused in-the-wild to help infostealers deploy post-exploitation payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.