shareip

Aliases: remotecmd

First seen
2020-03-15 00:00:00
Malware type
rat, backdoor
Profile updated
2026-07-07 15:19:43

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Shareip, also known as remotecmd, is a remote access tool used by threat actors to gain unauthorized access to systems. It provides attackers with the capability to execute remote commands and establish backdoor access for prolonged infiltration.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Shareip_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Shareip (report)
  • Broadcom/Symantec — Buckeye Cyberespionage Group Shifts Gaze Us Hong Kong (report)

External references