Tool
Gshell
- First Reported
- Jul 14, 2026
- Latest Reported
- Jul 14, 2026
Reported Context (1)
- 443 and 8083 self-identifying as a separate C2 framework. The subject and issuer fields consist of CN = Gshell Server and O = Gshell C2. We were unable to find prior public reporting documenting a framework under Hunt.io Details Suspected China-Linked Campaign Using Claude Code and DeepSeek Against Government Systems
Malware (2)
MITRE ATT&CK (7)
Vendors (5)
Products (6)
Tools (6)
Industries (7)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.