HomeSecurityHackers exploit Shellter tool to develop infostealer

Hackers exploit Shellter tool to develop infostealer

Shellter Project, the creator of a commercial AV/EDR bypass tool for penetration testing, has confirmed that hackers used its Shellter Elite in attacks, following a leak of the software by a customer.

See also: INTERPOL removes 20,000+ IPs linked to info-stealer

Hacker Shelter

The abuse of the tool has been going on for several months, and although security researchers spotted the activity in the field, Shellter did not receive any notification.

The tool's creator stressed that this is the first recorded incident of misuse since the strict licensing systemin February 2023. An update has been released to address the issue, which is not accessible to the "malicious customer."

Shellter Elite is a commercial AV/EDR bypass tool, used by security professionals (red teams and penetration testers) to covertly load payloads into legitimate Windows binaries, bypassing EDR tools during security exercises.

The tool includes static hiding techniques through polymorphism and dynamic runtime detection avoidance, leveraging methods such as AMSI bypass, ETW, anti-debug/virtual machine checks, call stack and module unhooking avoidance, as well as deceptive execution techniques

In a report published on July 3, Elastic Security Labs revealed that multiple malicious actors are abusing the Shellter Elite v11.0 to install infostealers, such as Rhadamanthys, Lumma , and Arechclient2.

See also: New InfoStealer Delivers EDDIESTEALER via Fake CAPTCHA

Elastic researchers found that the malicious activity began at least as early as April and that the malware was distributed through YouTube comments and phishing emails.

Hackers exploit Shellter tool to develop infostealer
Hackers exploit Shellter tool to develop infostealer

Based on unique timestamps of the licenses, they assumed that the threat actors were using a single leaked copy, which was later officially confirmed by Shellter.

Elastic has developed detection mechanisms for samples based on v11.0, so payloads created with that version of Shellter Elite can now be detected.

Shellter has released the Elite 11.1 version, which will only be distributed to trusted and vetted customers, explicitly excluding the one who leaked the previous version.

The tool's creator described the lack of communication from Elastic Security Labs as "irresponsible and unprofessional," accusing the company of not informing them of its findings in a timely manner.

See also: New Chihuahua Infostealer targets browser data

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The release of version 11.1, with stricter distribution terms, is an attempt to restore trust, but this incident is a reminder of the responsibility that both tool vendors and security researchers have to work closely together, especially when developments affect the security of the broader digital ecosystem.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS