Threat researchers investigating malware used to target companies in the aerospace and telecommunications sectors have discovered a new threat actor that has been conducting cyber espionage campaigns since at least 2018. Dubbed ShellClient, the malware is a remote access trojan (RAT) created with an emphasis on stealth and for “highly targeted cyber espionage operations.”.
Researchers attributed ShellClient to MalKamak, an unknown threat actor who used it for reconnaissance operations and to steal sensitive data from targets in the Middle East, the US, Russia, and Europe.
See also: How a coding bug turns AirTags into malware distributors

See also: Android malware has stolen money from 10 million users!
Stealthy RAT has been active since 2018
The ShellClient RAT appeared on threat researchers' radar in July during an incident response engagement that uncovered cyber espionage activity now referred to as Operation GhostShell.
Cybereason Nocturnus and Incident Response teams analyzed the malware and observed that it was running on infected machines disguised as “RuntimeBroker.exe,” a legitimate process that helps manage licenses for apps from the Microsoft Store.
The ShellClient variant used for the GhostShell feature shows a build date of May 22, 2021 and is listed as version 4.0.1.
Researchers found that its evolution began at least as early as November 2018 "from a simple standalone reverse shell to a covert espionage tool.".
With each of the six iterations discovered, the malware increased its functionality and switched between multiple protocols and methods for data exfiltration (e.g. FTP client, Dropbox account):
- The older variant, compiled in November 2018 – less sophisticated, works as a simple reverse shell
- V1 variant, compiled in November 2018 – has both client and server functionality, adds new persistence method disguised as Windows Defender update service
- V2.1, released in December 2018 – adds FTP and Telnet clients, AES encryption, auto-update feature
- Version V3.1, compiled in January 2019 – minor modifications, removes the server component
- The V4.0.0 variant, compiled in August 2021 – marks significant changes, such as better obfuscation and code protection via the Costura package, abandonment of the C2 domain used since 2018, and addition of a Dropbox client
See also: FinFisher malware: Infects Windows Boot Manager with UEFI bootkit
In its research, Cybereason looked for details that would link ShellClient to a known adversary, but concluded that the malware is operated by a new group called MalKamak, which is likely linked to Iranian hackers, as indicated by the code style overlap and techniques.
Researchers say the MalKamak group focuses on high-level cyber espionage operations, a theory supported by the low number of samples discovered since 2018.
Additionally, the file debugging path available in some ShellClients samples suggests that the malware is part of a confidential project by a military or intelligence agency.
Cybereason created a brief summary of how MalKamak operates, its capabilities, its infrastructure, and the types of victims it targets.
Information source: bleepingcomputer.com
