Financially motivated threat actors have abused an illicit copy of the commercial Shellter Elite v11.0 evasion framework since late April 2025 to build a loader delivering Lumma Stealer, ARECHCLIENT2/SECTOP RAT, and the Rhadamanthys information stealer. The campaigns used file-hosting links, phishing lures aimed at content creators, and malicious YouTube comments to distribute payloads; a shared embedded license-expiry timestamp indicates many samples may have been produced using a single compromised or illicit license.
The observed SHELLTER loader encrypts payloads with AES-128-CBC and employs polymorphic shellcode, ntdll remapping and unhooking, indirect system calls, call-stack corruption, AMSI bypasses, debugger and sandbox checks, and vectored-exception-handler API proxying to hinder detection and analysis. Elastic Security Labs released YARA rules and a dynamic unpacker to help defenders identify and inspect the malicious loader and its embedded malware.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The Shellter Project released version 11.0 of its commercial Shellter Elite evasion framework, intended for authorized red-team operations.
Multiple financially motivated campaigns began using an illicit copy of Shellter Elite v11.0 to package and load information stealers. LUMMA was distributed in Shellter-protected binaries, including files hosted on MediaFire.
Elastic Security Labs published YARA rules for Shellter-protected malware and the shared illicit-license value, and released a dynamic unpacker for extracting payload stages. The researchers cautioned that the unpacker should be run only in an isolated virtual machine because it maps potentially malicious code into memory.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.