Horse Shell
- First seen
- 2023-04-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:05:40
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities: * Remote shell: Execution of arbitrary shell commands on the infected router * File transfer: Upload and download files to and from the infected router. * SOCKS tunneling: Relay communication between different clients.
Reports & references
- research.checkpoint.com — The Dragon Who Sold His Camaro Analyzing Custom Router Implant (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Horseshell (report)