Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Analysis of BlueShell Variants Used by APT Groups

944b774d592f5e7fe2c34ac6c3abb2a77bfa96707c4f3c33ac77b8d54800244f

TLP:CLEAR
Active

SHA-256 Hash

Description

BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Analysis of BlueShell Variants Used by APT Groups
Pattern Type
STIX
Confidence
75%
Valid From
Jul 30, 2026 18:01
Total Sightings
0
Added
Jul 30, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 944b774d592f5e7fe2c34ac6c3abb2a77bfa96707c4f3c33ac77b8d54800244f

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.