Skip to main content

Threats Tagged 'supershell'

View all threats tagged with 'supershell'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: supershell

Threats Tagged 'supershell'

Click on any threat for detailed analysis and mitigation recommendations

An analysis of Chinese hosting environments reveals over 18,000 active command-and-control (C2) servers distributed across 48 infrastructure providers. C2 infrastructure dominates malicious activity at 84%, followed by phishing at 13%. China Unicom hosts nearly half of all observed C2 servers, with Alibaba Cloud and Tencent following. A small set of malware families, including Mozi, ARL, and Cobalt Strike, accounts for most C2 activity. The infrastructure supports both cybercrime and state-linked operations, with RATs, cryptominers, and APT tooling coexisting. High-trust networks like China169 Backbone and CERNET are actively exploited. This host-centric approach exposes long-running abuse patterns and infrastructure reuse across campaigns, enabling more resilient threat detection and mitigation strategies.

Join the discussion

Operation DRAGONCLONE is an advanced cyber espionage campaign targeting China Mobile Tietong and potentially European telecom organizations connected to Chinese infrastructure. It uses sophisticated malware loaders like VELETRIX and the VShell adversary simulation tool, delivered via malicious ZIP files exploiting DLL sideloading and anti-analysis techniques such as IPFuscation. The campaign is linked to China-nexus threat groups UNC5174 (Uteus) and Earth Lamia and employs tools including SuperShell, Cobalt Strike, and Asset Lighthouse System. Active since March 2025, it focuses on credential theft, network reconnaissance, and callback execution. Detection requires monitoring for specific malware behaviors, DLL sideloading, and network callbacks. Germany, France, and the UK are at heightened risk due to their telecom sectors and economic ties to China. The threat is assessed as high severity given its advanced evasion, espionage intent, and potential impact on critical telecom infrastructure.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: supershell
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses