Horse Shell

First seen
2023-04-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 13:05:40

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities: * Remote shell: Execution of arbitrary shell commands on the infected router * File transfer: Upload and download files to and from the infected router. * SOCKS tunneling: Relay communication between different clients.

Reports & references

  • research.checkpoint.com — The Dragon Who Sold His Camaro Analyzing Custom Router Implant (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Horseshell (report)

External references