Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlueShell은 Go 언어로 개발된 백도어 악성코드로서 깃허브에 공개되어 있으며 윈도우, 리눅스, 맥 운영체제를 지원한다.
Analysts at IIJ Security Diary identified the malware as a Linux variant of BlueShell used during post-compromise activity by BlackTech.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The loader decodes concealed data, decompresses the backdoor... The malware also checks part of the command server’s digital certificate before continuing its connection... Its renamed commands appear designed to slow analysis...
Once active, the backdoor reads its hidden settings from environment variables...
드로퍼는 이외에도 두 가지 특징이 존재하는데 하나는 BlueShell을 실행할 때 인자로 “/sbin/rpcd”를 전달하여 실행 중인 프로세스의 이름을 “/sbin/rpcd”로 위장한다는 점이다.
BlueShell 악성코드인 “/tmp/kthread”를 실행한 이후에는 삭제하기 때문에 BlueShell은 메모리 상에서만 동작하게 된다.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based Linux backdoor derived from an openly available remote-access tool. In the observed campaign it was deployed post-compromise via a loader, executed with disguised process metadata, removed from disk to hinder forensics, read hidden configuration from environment variables, collected host information, executed remote commands, transferred files, opened a shell, and created a SOCKS5 proxy. Newer variants also routed C2 through the victim organization's proxy server and validated part of the C2 certificate before connecting.
Go로 개발된 크로스플랫폼 백도어로, TLS로 C2 통신을 보호하며 원격 명령 실행, 파일 업로드/다운로드, Socks5 프록시 기능을 제공한다. 공개 소스 기반으로 여러 공격자가 Windows 및 Linux 공격에 사용한 사례가 소개된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.