Firewall Daily

Cyble Research Discovers ShadowHS, an In-Memory Linux Framework for Long-Term Access

Cyble Research & Intelligence Labs (CRIL) has uncovered a post-exploitation Linux framework called ShadowHS, designed for stealthy, in-memory operations. Unlike traditional malware, ShadowHS leverages a fileless architecture and a weaponized version of hackshell, enabling attackers to maintain long-term, operator-controlled access to compromised Linux systems. 

Fileless Execution and Weaponized Hackshell

The ShadowHS Linux framework operates entirely in memory, leaving no persistent binaries on disk. CRIL’s analysis revealed that the framework uses an encrypted shell loader to deploy a heavily modified version of hackshell, enabling an interactive post-exploitation environment.

The loader decrypts and reconstructs the payload in memory using AES‑256‑CBC encryption, Perl byte skipping, and gzip decompression. The payload is executed via /proc/<pid>/fd/<fd> with a spoofed argv[0], ensuring that no filesystem artifacts remain.

Payload Reconstruction & Fileless Execution (Source: CRIL)

Once active, ShadowHS prioritizes reconnaissance, fingerprinting host security measures, evaluating prior compromises, and providing an operator-controlled interface. Its runtime behavior is deliberately restrained, allowing attackers to selectively invoke capabilities such as credential access, lateral movement, privilege escalation, cryptomining, and covert data exfiltration. 

CRIL Observations on Operator-Centric Design

According to CRIL, ShadowHS reflects mature operator tradecraft rather than the patterns of opportunistic Linux malware. Its in-memory design allows operators to assess system security posture while avoiding traditional detection mechanisms.

The payload performs aggressive EDR and AV fingerprinting, checking for commercial endpoint tools such as CrowdStrike, Tanium, Sophos, and Microsoft Defender, as well as cloud and OT/ICS telemetry agents. 

Runtime Dependency Validation (Source: CRIL)

“ShadowHS demonstrates a clear separation between restrained runtime activity and extensive dormant capabilities,” CRIL notes. “This is indicative of a deliberate operator-driven post-exploitation platform rather than automated malware.” 

Covert Data Exfiltration

One of ShadowHS’s most notable features is its ability to exfiltrate data without using standard network channels. The Linux framework implements user-space tunneling over GSocket, replacing rsync’s default transport.

This allows files to be transferred stealthily across firewalls and restrictive network environments. CRIL observed two variants: one using DBus-based tunneling and another employing netcat-style GSocket tunnels, both preserving timestamps, permissions, and partial transfer state. 

Dormant Capabilities and Lateral Movement

ShadowHS also contains dormant modules that operators can activate on demand. These include: 

  • Memory dumping for credential theft
  • SSH-based lateral movement and brute-force scanning
  • Privilege escalation using kernel exploits
  • Cryptocurrency mining via XMRig, GMiner, and lolMiner

The framework incorporates anti-competition logic to detect and terminate rival malware, including miners like Rondo and Kinsing, as well as credential-stealing backdoors such as Ebury. It also evaluates kernel integrity and loaded modules, helping the operator determine if the host is already compromised or actively monitored. 

Implications for Threat Defense

The discovery of ShadowHS stresses the challenges organizations face in defending Linux environments against fileless, in-memory threats. CRIL notes that traditional signature-based antivirus solutions and file-based detection mechanisms are insufficient to detect frameworks like ShadowHS. Effective defense requires monitoring process behavior, kernel-level telemetry, and memory-resident activity. 

“ShadowHS represents a fully operator-controlled, adaptive Linux framework designed for stealth and long-term access,” CRIL stated. “Its use of a weaponized hackshell, fileless execution, and exfiltration methods highlights the growing need for proactive threat intelligence and advanced monitoring strategies.” 

See ShadowHS and new cyber threats in action, schedule your Cyble demo today, and gain real-time visibility into cyber risks before they impact your organization. 

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Recent Posts

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

This week’s roundup examines corporate cyberattacks, AI security risks, Microsoft zero-days, logistics disruption and threats targeting personal accounts.

3 days ago

AI Won’t Replace Cybersecurity Jobs, It’ll Replace the Toil – Harsha Reddy Explains What’s Next

As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question…

3 days ago

CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

A cyberattack on CEVA Logistics halted shipments at eight warehouses and exposed customer data tied to Valve, Ajax, and De…

4 days ago

NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management

NIST seeks input on modernizing the National Vulnerability Database as AI reshapes vulnerability management, risk assessment and remediation.

4 days ago

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site.

4 days ago

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days

Microsoft’s August 2026 Patch Tuesday fixes roughly 400 flaws, including three Zero-days, with one actively exploited and two publicly disclosed.

5 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More