DaveShell is an open source shellcode loader/in-memory dropper that relies on reflective injection. The provided reporting describes it as a publicly available DAVESHELL launcher and notes its integration into several related in-memory droppers, suggesting possible use by common crypting-service operators. Itochu researchers reported decrypting payloads from Tropic Trooper-linked infrastructure and identified DaveShell alongside Donut loader, marking the first observed use of these open source loaders in Tropic Trooper activity. In that broader activity, Tropic Trooper—a China-linked APT also known as Pirate Panda, KeyBoy, APT23, Bronze Hobart, and Earth Centaur—targeted specific individuals in Japan, Taiwan, and South Korea, with investigations also tying the group to DNS hijacking via a compromised home router, software-update abuse, exposed S3-hosted tooling, and continued use of Cobalt Strike and other malware. High-confidence content specific to DaveShell is limited to its role as a reflective in-memory dropper/launcher and its observed use in Tropic Trooper operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The integration of the publicly available DAVESHELL launcher into several related in-memory droppers may also suggest that at least some crypting services are provided by a common actor.
We decrypted these and found new malware, including DaveShell and Donut loader, which are two open source loaders being observed for first time in Tropic Trooper activity.
DAVESHELL — Shellcode that functions as an in memory dropper relying on reflective injection.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Since at least February 2020, FIN12 has leveraged a series of in-memory droppers including, MALTSHAKE, ICECANDLE, WHITEDAGGER, WEIRDLOOP, and templates associated with Cobalt Strike's Artifact Kit to deploy various malware payloads.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open source loader newly observed in Tropic Trooper activity.
Shellcode-based in-memory dropper that relies on reflective injection.
Memory-only launcher embedded in several droppers used in FIN12-related activity to load PE payloads in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.