tsh
Aliases: TINYSHELL
- First seen
- 2011-05-01 00:00:00
- Malware type
- backdoor, webshell
- Family
- Malware family
- Profile updated
- 2026-07-07 14:22:57
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
TSH, also known as TINYSHELL, is a lightweight remote access tool used to establish a backdoor connection for unauthorized access and control. It is often used by threat actors to maintain persistence within compromised networks, primarily targeting government and financial sectors.
Detection coverage
- 3 YARA rules
Detection rules
- SEKOIA_Malware_Tinyshell_Strings (yara-rule)
- SIGNATURE_BASE_EXT_HKTL_MAL_Tinyshell_Backdoor (yara-rule)
- SIGNATURE_BASE_EXT_HKTL_MAL_Tinyshell_Backdoor_SPARC (yara-rule)
Reports & references
- rapid7.com — Tr Bpfdoor Telecom Networks Sleeper Cells Threat Research Report (report)
- cloud.google.com — China Nexus Espionage Targets Juniper Routers (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Tsh (report)
- github.com — Tsh (report)
- supportportal.juniper.net — 069Dp00000Fzdmiiar (report)