Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Analysis of BlueShell Variants Used by APT Groups

d7513a05ff14ee84594ec97c1defa37a1e430770

TLP:CLEAR
Active

SHA-1 Hash

Description

BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Analysis of BlueShell Variants Used by APT Groups
Pattern Type
STIX
Confidence
75%
Valid From
Jul 30, 2026 18:01
Total Sightings
0
Added
Jul 30, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of d7513a05ff14ee84594ec97c1defa37a1e430770

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.